<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-12-27T11:51:51</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20110004" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0004: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0004.html" />
          <reference source="CVE" ref_id="CVE-2010-3432" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3432.html" />
          <reference source="CVE" ref_id="CVE-2010-3442" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3442.html" />
          <reference source="CVE" ref_id="CVE-2010-3699" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3699.html" />
          <reference source="CVE" ref_id="CVE-2010-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3858.html" />
          <reference source="CVE" ref_id="CVE-2010-3859" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3859.html" />
          <reference source="CVE" ref_id="CVE-2010-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3865.html" />
          <reference source="CVE" ref_id="CVE-2010-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3876.html" />
          <reference source="CVE" ref_id="CVE-2010-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3880.html" />
          <reference source="CVE" ref_id="CVE-2010-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4083.html" />
          <reference source="CVE" ref_id="CVE-2010-4157" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4157.html" />
          <reference source="CVE" ref_id="CVE-2010-4161" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4161.html" />
          <reference source="CVE" ref_id="CVE-2010-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4242.html" />
          <reference source="CVE" ref_id="CVE-2010-4247" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4247.html" />
          <reference source="CVE" ref_id="CVE-2010-4248" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4248.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in sctp_packet_config() in the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation. A remote attacker
could use this flaw to cause a denial of service. (CVE-2010-3432,
Important)

* A missing integer overflow check was found in snd_ctl_new() in the Linux
kernel's sound subsystem. A local, unprivileged user on a 32-bit system
could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-3442, Important)

* A heap overflow flaw in the Linux kernel's Transparent Inter-Process
Communication protocol (TIPC) implementation could allow a local,
unprivileged user to escalate their privileges. (CVE-2010-3859, Important)

* An integer overflow flaw was found in the Linux kernel's Reliable
Datagram Sockets (RDS) protocol implementation. A local, unprivileged user
could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-3865, Important)

* A flaw was found in the Xenbus code for the unified block-device I/O
interface back end. A privileged guest user could use this flaw to cause a
denial of service on the host system running the Xen hypervisor.
(CVE-2010-3699, Moderate)

* Missing sanity checks were found in setup_arg_pages() in the Linux
kernel. When making the size of the argument and environment area on the
stack very large, it could trigger a BUG_ON(), resulting in a local denial
of service. (CVE-2010-3858, Moderate)

* A flaw was found in inet_csk_diag_dump() in the Linux kernel's module for
monitoring the sockets of INET transport protocols. By sending a netlink
message with certain bytecode, a local, unprivileged user could cause a
denial of service. (CVE-2010-3880, Moderate)

* Missing sanity checks were found in gdth_ioctl_alloc() in the gdth driver
in the Linux kernel. A local user with access to "/dev/gdth" on a 64-bit
system could use this flaw to cause a denial of service or escalate their
privileges. (CVE-2010-4157, Moderate)

* The fix for Red Hat Bugzilla bug 484590 as provided in RHSA-2009:1243
introduced a regression. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2010-4161, Moderate)

* A NULL pointer dereference flaw was found in the Bluetooth HCI UART
driver in the Linux kernel. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4242, Moderate)

* It was found that a malicious guest running on the Xen hypervisor could
place invalid data in the memory that the guest shared with the blkback and
blktap back-end drivers, resulting in a denial of service on the host
system. (CVE-2010-4247, Moderate)

* A flaw was found in the Linux kernel's CPU time clocks implementation for
the POSIX clock interface. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4248, Moderate)

* Missing initialization flaws in the Linux kernel could lead to
information leaks. (CVE-2010-3876, CVE-2010-4083, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-3442,
CVE-2010-4161, and CVE-2010-4083; Thomas Pollet for reporting
CVE-2010-3865; Brad Spengler for reporting CVE-2010-3858; Nelson Elhage for
reporting CVE-2010-3880; Alan Cox for reporting CVE-2010-4242; and Vasiliy
Kulikov for reporting CVE-2010-3876.

This update also fixes several bugs and adds an enhancement. Documentation
for the bug fixes and the enhancement will be available shortly from the
Technical Notes document, linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-04" />
        <updated date="2011-01-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3432.html">CVE-2010-3432</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3442.html">CVE-2010-3442</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3699.html">CVE-2010-3699</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3858.html">CVE-2010-3858</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3859.html">CVE-2010-3859</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3865.html">CVE-2010-3865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3876.html">CVE-2010-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3880.html">CVE-2010-3880</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4083.html">CVE-2010-4083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4157.html">CVE-2010-4157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4161.html">CVE-2010-4161</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4242.html">CVE-2010-4242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4247.html">CVE-2010-4247</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4248.html">CVE-2010-4248</cve>
                <bugzilla href="http://bugzilla.redhat.com/636411" id="636411">CVE-2010-3699 kernel: guest->host denial of service from invalid xenbus transitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637675" id="637675">CVE-2010-3432 kernel: sctp: do not reset the packet during sctp_packet_config</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638478" id="638478">CVE-2010-3442 kernel: prevent heap corruption in snd_ctl_new()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641410" id="641410">CVE-2010-4242 kernel: missing tty ops write function presence check in hci_uart_tty_open()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643339" id="643339">[Intel/Cisco 5.6 Bug] ixgbe: include ability to disable MSI-X [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643344" id="643344">kernel: Problem with execve(2) reintroduced [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643345" id="643345">netback does not properly get to the Connected state after it's been Closed [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643347" id="643347">kernel: security: testing the wrong variable in create_by_name() [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645222" id="645222">CVE-2010-3858 kernel: setup_arg_pages: diagnose excessive argument size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645867" id="645867">CVE-2010-3859 kernel: tipc: heap overflow in tipc_msg_build()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646765" id="646765">RHEL5.6 Include DL580 G7 in bfsort whitelist [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647416" id="647416">CVE-2010-3865 kernel: iovec integer overflow in net/rds/rdma.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647681" id="647681">bond0 only works in promisc mode [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648673" id="648673">CVE-2010-4083 kernel: ipc/sem.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648938" id="648938">x86_64 host on Nehalem-EX machines will panic when installing a 4.8 GA kvm guest [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649255" id="649255">bnx2 adapter periodically dropping received packets [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649715" id="649715">CVE-2010-3876 kernel: net/packet/af_packet.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651147" id="651147">CVE-2010-4157 kernel: gdth: integer overflow in ioc_general()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651264" id="651264">CVE-2010-3880 kernel: logic error in INET_DIAG bytecode auditing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651805" id="651805">GFS2: stuck in inode wait, no glocks stuck [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651811" id="651811">GFS2: BUG_ON kernel panic in gfs2_glock_hold on 2.6.18-226 [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651818" id="651818">[5.5] Hangs up during booting due to a spinlock problem. [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652534" id="652534">CVE-2010-4161 kernel: rhel5 commit 6865201191 caused deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652561" id="652561">Scheduling while atomic when removing slave tg3 interface from bonding [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653335" id="653335">flock performance with DLM in RHEL 5.5 [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656206" id="656206">CVE-2010-4247 xen: request-processing loop is unbounded in blkback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656264" id="656264">CVE-2010-4248 kernel: posix-cpu-timers: workaround to suppress the problems with mt exec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657028" id="657028">[NetApp 5.6 bug] SCSI ALUA handler fails to handle ALUA transitioning properly [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657029" id="657029">[NetApp 5.6 bug] qla2xxx: Kernel panic on qla24xx_queuecommand [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657319" id="657319">[Stratus 5.6 bug] System crashes at uhci_scan_schedule(). [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658079" id="658079">lpfc: set heartbeat timer off by default [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658378" id="658378">lpfc: fix a BUG_ON in lpfc_abort_handler [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658379" id="658379">lpfc: fix panic in lpfc_scsi_cmd_iocb_cmpl [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658520" id="658520">add round_jiffies_up and related routines [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658857" id="658857">dcache unused accounting problem [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658864" id="658864">lpfc: fix crashes on NULL pnode dereference [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658934" id="658934">[NetApp 5.6 bug] regression: allow offlined devs to be set to running [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663353" id="663353">System crashes at .nfs_flush_incompatible [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663381" id="663381">[REG][5.6] kernel panic occurs by writing a file on optional mount "sync/noac" of NFSv4. [rhel-5.5.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664416" id="664416">[REG][5.6] kernel panic occurs by reading an empty file on optional mount "sync/noac" of NFSv4. [rhel-5.5.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004004" comment="kernel-headers is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004002" comment="kernel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004024" comment="kernel-doc is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004020" comment="kernel-PAE-devel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004008" comment="kernel-devel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004010" comment="kernel-debug is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004016" comment="kernel-kdump is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004012" comment="kernel-xen-devel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004014" comment="kernel-debug-devel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004022" comment="kernel-PAE is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004018" comment="kernel-kdump-devel is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004006" comment="kernel-xen is earlier than 0:2.6.18-194.32.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110007" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0007: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0007-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0007.html" />
          <reference source="CVE" ref_id="CVE-2010-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2492.html" />
          <reference source="CVE" ref_id="CVE-2010-3067" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3067.html" />
          <reference source="CVE" ref_id="CVE-2010-3078" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3078.html" />
          <reference source="CVE" ref_id="CVE-2010-3080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3080.html" />
          <reference source="CVE" ref_id="CVE-2010-3298" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3298.html" />
          <reference source="CVE" ref_id="CVE-2010-3477" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3477.html" />
          <reference source="CVE" ref_id="CVE-2010-3861" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3861.html" />
          <reference source="CVE" ref_id="CVE-2010-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3865.html" />
          <reference source="CVE" ref_id="CVE-2010-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3874.html" />
          <reference source="CVE" ref_id="CVE-2010-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3876.html" />
          <reference source="CVE" ref_id="CVE-2010-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3880.html" />
          <reference source="CVE" ref_id="CVE-2010-4072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4072.html" />
          <reference source="CVE" ref_id="CVE-2010-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4073.html" />
          <reference source="CVE" ref_id="CVE-2010-4074" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4074.html" />
          <reference source="CVE" ref_id="CVE-2010-4075" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4075.html" />
          <reference source="CVE" ref_id="CVE-2010-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4077.html" />
          <reference source="CVE" ref_id="CVE-2010-4079" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4079.html" />
          <reference source="CVE" ref_id="CVE-2010-4080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4080.html" />
          <reference source="CVE" ref_id="CVE-2010-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4081.html" />
          <reference source="CVE" ref_id="CVE-2010-4082" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4082.html" />
          <reference source="CVE" ref_id="CVE-2010-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4083.html" />
          <reference source="CVE" ref_id="CVE-2010-4158" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4158.html" />
          <reference source="CVE" ref_id="CVE-2010-4160" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4160.html" />
          <reference source="CVE" ref_id="CVE-2010-4162" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4162.html" />
          <reference source="CVE" ref_id="CVE-2010-4163" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4163.html" />
          <reference source="CVE" ref_id="CVE-2010-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4242.html" />
          <reference source="CVE" ref_id="CVE-2010-4248" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4248.html" />
          <reference source="CVE" ref_id="CVE-2010-4249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4249.html" />
          <reference source="CVE" ref_id="CVE-2010-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4263.html" />
          <reference source="CVE" ref_id="CVE-2010-4525" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4525.html" />
          <reference source="CVE" ref_id="CVE-2010-4668" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4668.html" />
    
    <description>* Buffer overflow in eCryptfs. When /dev/ecryptfs has world writable
permissions (which it does not, by default, on Red Hat Enterprise Linux 6),
a local, unprivileged user could use this flaw to cause a denial of service
or possibly escalate their privileges. (CVE-2010-2492, Important)

* Integer overflow in the RDS protocol implementation could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-3865, Important)

* Missing boundary checks in the PPP over L2TP sockets implementation could
allow a local, unprivileged user to cause a denial of service or escalate
their privileges. (CVE-2010-4160, Important)

* NULL pointer dereference in the igb driver. If both Single Root I/O
Virtualization (SR-IOV) and promiscuous mode were enabled on an interface
using igb, it could result in a denial of service when a tagged VLAN packet
is received on that interface. (CVE-2010-4263, Important)

* Missing initialization flaw in the XFS file system implementation, and in
the network traffic policing implementation, could allow a local,
unprivileged user to cause an information leak. (CVE-2010-3078,
CVE-2010-3477, Moderate)

* NULL pointer dereference in the Open Sound System compatible sequencer
driver could allow a local, unprivileged user with access to /dev/sequencer
to cause a denial of service. /dev/sequencer is only accessible to root and
users in the audio group by default. (CVE-2010-3080, Moderate)

* Flaw in the ethtool IOCTL handler could allow a local user to cause an
information leak. (CVE-2010-3861, Moderate)

* Flaw in bcm_connect() in the Controller Area Network (CAN) Broadcast
Manager. On 64-bit systems, writing the socket address may overflow the
procname character array. (CVE-2010-3874, Moderate)

* Flaw in the module for monitoring the sockets of INET transport
protocols could allow a local, unprivileged user to cause a denial of
service. (CVE-2010-3880, Moderate)

* Missing boundary checks in the block layer implementation could allow a
local, unprivileged user to cause a denial of service. (CVE-2010-4162,
CVE-2010-4163, CVE-2010-4668, Moderate)

* NULL pointer dereference in the Bluetooth HCI UART driver could allow a
local, unprivileged user to cause a denial of service. (CVE-2010-4242,
Moderate)

* Flaw in the Linux kernel CPU time clocks implementation for the POSIX
clock interface could allow a local, unprivileged user to cause a denial of
service. (CVE-2010-4248, Moderate)

* Flaw in the garbage collector for AF_UNIX sockets could allow a local,
unprivileged user to trigger a denial of service. (CVE-2010-4249, Moderate)

* Missing upper bound integer check in the AIO implementation could allow a
local, unprivileged user to cause an information leak. (CVE-2010-3067, Low)

* Missing initialization flaws could lead to information leaks.
(CVE-2010-3298, CVE-2010-3876, CVE-2010-4072, CVE-2010-4073, CVE-2010-4074,
CVE-2010-4075, CVE-2010-4077, CVE-2010-4079, CVE-2010-4080, CVE-2010-4081,
CVE-2010-4082, CVE-2010-4083, CVE-2010-4158, Low)

* Missing initialization flaw in KVM could allow a privileged host user
with access to /dev/kvm to cause an information leak. (CVE-2010-4525, Low)

Red Hat would like to thank Andre Osterhues for reporting CVE-2010-2492;
Thomas Pollet for reporting CVE-2010-3865; Dan Rosenberg for reporting
CVE-2010-4160, CVE-2010-3078, CVE-2010-3874, CVE-2010-4162, CVE-2010-4163,
CVE-2010-3298, CVE-2010-4073, CVE-2010-4074, CVE-2010-4075, CVE-2010-4077,
CVE-2010-4079, CVE-2010-4080, CVE-2010-4081, CVE-2010-4082, CVE-2010-4083,
and CVE-2010-4158; Kosuke Tatsukawa for reporting CVE-2010-4263; Tavis
Ormandy for reporting CVE-2010-3080 and CVE-2010-3067; Kees Cook for
reporting CVE-2010-3861 and CVE-2010-4072; Nelson Elhage for reporting
CVE-2010-3880; Alan Cox for reporting CVE-2010-4242; Vegard Nossum for
reporting CVE-2010-4249; Vasiliy Kulikov for reporting CVE-2010-3876; and
Stephan Mueller of atsec information security for reporting CVE-2010-4525.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-11" />
        <updated date="2011-01-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2492.html">CVE-2010-2492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3067.html">CVE-2010-3067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3078.html">CVE-2010-3078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3080.html">CVE-2010-3080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3298.html">CVE-2010-3298</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3477.html">CVE-2010-3477</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3861.html">CVE-2010-3861</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3865.html">CVE-2010-3865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3874.html">CVE-2010-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3876.html">CVE-2010-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3880.html">CVE-2010-3880</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4072.html">CVE-2010-4072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4073.html">CVE-2010-4073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4074.html">CVE-2010-4074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4075.html">CVE-2010-4075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4077.html">CVE-2010-4077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4079.html">CVE-2010-4079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4080.html">CVE-2010-4080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4081.html">CVE-2010-4081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4082.html">CVE-2010-4082</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4083.html">CVE-2010-4083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4158.html">CVE-2010-4158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4160.html">CVE-2010-4160</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4162.html">CVE-2010-4162</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4163.html">CVE-2010-4163</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4242.html">CVE-2010-4242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4248.html">CVE-2010-4248</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4249.html">CVE-2010-4249</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4263.html">CVE-2010-4263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4525.html">CVE-2010-4525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4668.html">CVE-2010-4668</cve>
                <bugzilla href="http://bugzilla.redhat.com/611385" id="611385">CVE-2010-2492 kernel: ecryptfs_uid_hash() buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629441" id="629441">CVE-2010-3067 kernel: do_io_submit() infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630551" id="630551">CVE-2010-3080 kernel: /dev/sequencer open failure is not handled correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630804" id="630804">CVE-2010-3078 kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633140" id="633140">CVE-2010-3298 kernel: drivers/net/usb/hso.c: prevent reading uninitialized memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636386" id="636386">CVE-2010-3477 kernel: net/sched/act_police.c infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641410" id="641410">CVE-2010-4242 kernel: missing tty ops write function presence check in hci_uart_tty_open()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646725" id="646725">CVE-2010-3861 kernel: heap contents leak from ETHTOOL_GRXCLSRLALL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647391" id="647391">kernel BUG at mm/migrate.c:113! [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647416" id="647416">CVE-2010-3865 kernel: iovec integer overflow in net/rds/rdma.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648408" id="648408">Do not mix FMODE_ and O_ flags with break_lease() and may_open() [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648656" id="648656">CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648658" id="648658">CVE-2010-4073 kernel: ipc/compat*.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648659" id="648659">CVE-2010-4074 kernel: drivers/usb/serial/mos*.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648660" id="648660">CVE-2010-4075 kernel: drivers/serial/serial_core.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648663" id="648663">CVE-2010-4077 kernel: drivers/char/nozomi.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648666" id="648666">CVE-2010-4079 kernel: drivers/video/ivtv/ivtvfb.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648669" id="648669">CVE-2010-4080 kernel: drivers/sound/pci/rme9652/hdsp.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648670" id="648670">CVE-2010-4081 kernel: drivers/sound/pci/rme9652/hdspm.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648671" id="648671">CVE-2010-4082 kernel: drivers/video/via/ioctl.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648673" id="648673">CVE-2010-4083 kernel: ipc/sem.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649695" id="649695">CVE-2010-3874 kernel: CAN minor heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649715" id="649715">CVE-2010-3876 kernel: net/packet/af_packet.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651264" id="651264">CVE-2010-3880 kernel: logic error in INET_DIAG bytecode auditing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651698" id="651698">CVE-2010-4158 kernel: socket filters infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651892" id="651892">CVE-2010-4160 kernel: L2TP send buffer allocation size overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652529" id="652529">CVE-2010-4162 kernel: bio: integer overflow page count when mapping/copying user data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652957" id="652957">CVE-2010-4163 CVE-2010-4668 kernel: panic when submitting certain 0-length I/O requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653340" id="653340">[kvm] VIRT-IO NIC state is reported as 'unknown' on vm running over RHEL6 host [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656264" id="656264">CVE-2010-4248 kernel: posix-cpu-timers: workaround to suppress the problems with mt exec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656756" id="656756">CVE-2010-4249 kernel: unix socket local dos</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658879" id="658879">kernel 2.6.32-84.el6 breaks systemtap [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659611" id="659611">lpfc: Fixed crashes for BUG_ONs hit in the lpfc_abort_handler [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660188" id="660188">CVE-2010-4263 kernel: igb panics when receiving tag vlan packet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660244" id="660244">lpfc: Set heartbeat timer off by default [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660591" id="660591">neighbour update causes an Oops when using tunnel device [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665470" id="665470">CVE-2010-4525 kvm: x86: zero kvm_vcpu_events->interrupt.pad infoleak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007023" comment="kernel-firmware is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007009" comment="kernel-headers is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007005" comment="kernel is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007025" comment="kernel-doc is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007013" comment="kernel-devel is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007021" comment="perf is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007011" comment="kernel-debug is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007017" comment="kernel-kdump is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007015" comment="kernel-debug-devel is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007019" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007007" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.14.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110009" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0009: evince security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0009.html" />
          <reference source="CVE" ref_id="CVE-2010-2640" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2640.html" />
          <reference source="CVE" ref_id="CVE-2010-2641" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2641.html" />
          <reference source="CVE" ref_id="CVE-2010-2642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2642.html" />
          <reference source="CVE" ref_id="CVE-2010-2643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2643.html" />
    
    <description>Evince is a document viewer.

An array index error was found in the DeVice Independent (DVI) renderer's
PK and VF font file parsers. A DVI file that references a specially-crafted
font file could, when opened, cause Evince to crash or, potentially,
execute arbitrary code with the privileges of the user running Evince.
(CVE-2010-2640, CVE-2010-2641)

A heap-based buffer overflow flaw was found in the DVI renderer's AFM font
file parser. A DVI file that references a specially-crafted font file
could, when opened, cause Evince to crash or, potentially, execute
arbitrary code with the privileges of the user running Evince.
(CVE-2010-2642)

An integer overflow flaw was found in the DVI renderer's TFM font file
parser. A DVI file that references a specially-crafted font file could,
when opened, cause Evince to crash or, potentially, execute arbitrary code
with the privileges of the user running Evince. (CVE-2010-2643)

Note: The above issues are not exploitable unless an attacker can trick the
user into installing a malicious font file.

Red Hat would like to thank the Evince development team for reporting these
issues.  Upstream acknowledges Jon Larimer of IBM X-Force as the original
reporter of these issues.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-06" />
        <updated date="2011-01-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2640.html">CVE-2010-2640</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2641.html">CVE-2010-2641</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2642.html">CVE-2010-2642</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2643.html">CVE-2010-2643</cve>
                <bugzilla href="http://bugzilla.redhat.com/666313" id="666313">CVE-2010-2640 evince: Array index errror in DVI file PK font parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666314" id="666314">CVE-2010-2641 evince: Array index errror in DVI file VF font parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666318" id="666318">CVE-2010-2642 evince, t1lib: Heap based buffer overflow in DVI file AFM font parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666321" id="666321">CVE-2010-2643 evince: Integer overflow in DVI file TFM font parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110009005" comment="evince is earlier than 0:2.28.2-14.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110009006" comment="evince is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110009007" comment="evince-libs is earlier than 0:2.28.2-14.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110009008" comment="evince-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110009011" comment="evince-dvi is earlier than 0:2.28.2-14.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110009012" comment="evince-dvi is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110009009" comment="evince-devel is earlier than 0:2.28.2-14.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110009010" comment="evince-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110013" version="503" class="patch">
      <metadata>
        <title>RHSA-2011:0013: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0013-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0013.html" />
          <reference source="CVE" ref_id="CVE-2010-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4538.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

An array index error, leading to a stack-based buffer overflow, was found
in the Wireshark ENTTEC dissector. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2010-4538)

Users of Wireshark should upgrade to these updated packages, which contain
a backported patch to correct this issue. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-10" />
        <updated date="2011-01-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4538.html">CVE-2010-4538</cve>
                <bugzilla href="http://bugzilla.redhat.com/666894" id="666894">CVE-2010-4538 Wireshark: Stack-based array index error in ENTTEC dissector (upstream bug #5539)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013002" comment="wireshark is earlier than 0:1.0.15-1.el5_5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013004" comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013014" comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013015" comment="wireshark-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013010" comment="wireshark is earlier than 0:1.2.13-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013011" comment="wireshark is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013012" comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013013" comment="wireshark-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013017" comment="wireshark is earlier than 0:1.0.15-1.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013018" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013019" comment="wireshark-gnome is earlier than 0:1.0.15-1.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013020" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110017" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0017: Red Hat Enterprise Linux 5.6 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0017.html" />
          <reference source="CVE" ref_id="CVE-2010-3296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3296.html" />
          <reference source="CVE" ref_id="CVE-2010-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3877.html" />
          <reference source="CVE" ref_id="CVE-2010-4072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4072.html" />
          <reference source="CVE" ref_id="CVE-2010-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4073.html" />
          <reference source="CVE" ref_id="CVE-2010-4075" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4075.html" />
          <reference source="CVE" ref_id="CVE-2010-4080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4080.html" />
          <reference source="CVE" ref_id="CVE-2010-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4081.html" />
          <reference source="CVE" ref_id="CVE-2010-4158" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4158.html" />
          <reference source="CVE" ref_id="CVE-2010-4238" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4238.html" />
          <reference source="CVE" ref_id="CVE-2010-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4243.html" />
          <reference source="CVE" ref_id="CVE-2010-4255" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4255.html" />
          <reference source="CVE" ref_id="CVE-2010-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4263.html" />
          <reference source="CVE" ref_id="CVE-2010-4343" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4343.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the igb driver in the Linux
kernel. If both the Single Root I/O Virtualization (SR-IOV) feature and
promiscuous mode were enabled on an interface using igb, it could result in
a denial of service when a tagged VLAN packet is received on that
interface. (CVE-2010-4263, Important)

* A missing sanity check was found in vbd_create() in the Xen hypervisor
implementation. As CD-ROM drives are not supported by the blkback back-end
driver, attempting to use a virtual CD-ROM drive with blkback could trigger
a denial of service (crash) on the host system running the Xen hypervisor.
(CVE-2010-4238, Moderate)

* A flaw was found in the Linux kernel execve() system call implementation.
A local, unprivileged user could cause large amounts of memory to be
allocated but not visible to the OOM (Out of Memory) killer, triggering a
denial of service. (CVE-2010-4243, Moderate)

* A flaw was found in fixup_page_fault() in the Xen hypervisor
implementation. If a 64-bit para-virtualized guest accessed a certain area
of memory, it could cause a denial of service on the host system running
the Xen hypervisor. (CVE-2010-4255, Moderate)

* A missing initialization flaw was found in the bfa driver used by Brocade
Fibre Channel Host Bus Adapters. A local, unprivileged user could use this
flaw to cause a denial of service by reading a file in the
"/sys/class/fc_host/host#/statistics/" directory. (CVE-2010-4343, Moderate)

* Missing initialization flaws in the Linux kernel could lead to
information leaks. (CVE-2010-3296, CVE-2010-3877, CVE-2010-4072,
CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4158,
Low)

Red Hat would like to thank Kosuke Tatsukawa for reporting CVE-2010-4263;
Vladymyr Denysov for reporting CVE-2010-4238; Brad Spengler for reporting
CVE-2010-4243; Dan Rosenberg for reporting CVE-2010-3296, CVE-2010-4073,
CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, and CVE-2010-4158; Vasiliy
Kulikov for reporting CVE-2010-3877; and Kees Cook for reporting
CVE-2010-4072.

These updated packages also include several hundred bug fixes for and
enhancements to the Linux kernel. Space precludes documenting each of these
changes in this advisory and users are directed to the Red Hat Enterprise
Linux 5.6 Release Notes for information on the most significant of these
changes:

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.6_Release_Notes/index.html

Refer to the kernel chapter in the Red Hat Enterprise Linux 5.6 Technical
Notes for further information:

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.6_Technical_Notes/kernel.html

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which address these vulnerabilities as well as fixing the bugs
and adding the enhancements noted in the Red Hat Enterprise Linux 5.6
Release Notes and Technical Notes. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-13" />
        <updated date="2011-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3296.html">CVE-2010-3296</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3877.html">CVE-2010-3877</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4072.html">CVE-2010-4072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4073.html">CVE-2010-4073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4075.html">CVE-2010-4075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4080.html">CVE-2010-4080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4081.html">CVE-2010-4081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4158.html">CVE-2010-4158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4238.html">CVE-2010-4238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4243.html">CVE-2010-4243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4255.html">CVE-2010-4255</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4263.html">CVE-2010-4263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4343.html">CVE-2010-4343</cve>
                <bugzilla href="http://bugzilla.redhat.com/237372" id="237372">Marvell PATA not supported</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429102" id="429102">Allocations on resume path can cause deadlock due to attempting to swap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441243" id="441243">kernel keyring quotas exceeded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455323" id="455323">No support for upstream /proc/sys/kernel/nmi_watchdog.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456765" id="456765">kabitool blocks custom kernel builds when kernel version > 2.6.18-53.1.21.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459901" id="459901">race condition between AIO and setresuid()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466088" id="466088">dm-snapshot: very slow write to snapshot origin when copy-on-write occurs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466157" id="466157">kernel doesn't supply memory fields in getrusage, /usr/bin/time anything shows "... (0avgtext+0avgdata 0maxresident)k ..."</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470801" id="470801">Read from /proc/xen/xenbus does not honor O_NONBLOCK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479418" id="479418">second cifs mount to samba server fails when samba using security=ADS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485903" id="485903">[RHEL5] Netfilter modules unloading hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488882" id="488882">cxgb3 driver very slow under Xen with HW acceleration enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493047" id="493047">Oprofile - Add Dunnington processors to the list of ppro cores</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494400" id="494400">TCP: Treason uncloaked! during Network Stress Testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496127" id="496127">[RHEL5.5] e1000e devices fail to initialize interrupts properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499553" id="499553">Cannot generate proper stacktrace on xen-ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503864" id="503864">The USB storage cannot use >2TB.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504188" id="504188">GFS1 vs GFS2 performance issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506694" id="506694">kdump hangs up if INIT is received while kdump is starting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507846" id="507846">Balloon driver gives up too easily when ballooning up under memory pressure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513934" id="513934">Keyboard LEDs constantly lit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516289" id="516289">bonding: backport code to allow user-controlled output slave detection.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516851" id="516851">[Stratus 5.6 bug] System crashes at uhci_scan_schedule().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516985" id="516985">When bonding is used and IPV6 is enabled the message of 'kernel: bond0: duplicate address detected!' is output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521878" id="521878">Fix instances of #!/usr/bin/env python in kernel-devel-packages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523341" id="523341">PCI SR-IOV BAR resources can't be reliably mapped</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523920" id="523920">[Adaptec/HCL 5.6 bug] Problems with aacraid - File system going into read-only.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529914" id="529914">GFS2 fatal: filesystem consistency error on rename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530123" id="530123">[Dell 5.5 FEAT] autoload tpm_tis driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533093" id="533093">Certain newer WDC SATA drives identified as SEMB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533391" id="533391">Kernel panic: EDAC MC0: INTERNAL ERROR: channel-b out of range</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/538022" id="538022">java.util.concurrent: long delay and intervals drift since kernel update to 164</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539560" id="539560">tcp_disconnect should clear all of tp->rx_opt ....</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539626" id="539626">default txqueuelen of vif device is too small</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/540786" id="540786">support supplementary groups of tun/tap devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/541224" id="541224">net:  possible leak of dst_entry (ipv4)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546060" id="546060">soft lockup while unmounting a read-only filesystem with errors (As per Redhat Bug #429054)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546455" id="546455">kernel bug: quota file size not a multiple of struct gfs2_quota</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546554" id="546554">kernel: no clue to find what is happening when hitting a lockdep limit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546700" id="546700">Deadlock in aio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/551028" id="551028">nfsv4 hangs -- kernel: decode_op_hdr: reply buffer overflowed in line 2121</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/552574" id="552574">Guest could not join the multicast group with virtio NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/552886" id="552886">[RHEL5] ip_mc_sf_allow() has a lock problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/553407" id="553407">nanosleep() is unstable on xen kernel and ntpd with -x option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/554706" id="554706">Kernel: network: bonding: scheduling while atomic: ifdown-eth/0x00000100/21775</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/554872" id="554872">Periodic ata exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x6 frozen messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/555197" id="555197">dm-raid1: fix data lost at mirror log failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/555708" id="555708">kABI whitelist request for Fujitsu modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/555910" id="555910">xen migration fails when a full virt guest uses the xen-vnif driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/556476" id="556476">Update sfc driver (add SFC9000 support)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/557423" id="557423">nfs: sys_read  sometimes returns -EIO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/558999" id="558999">[Broadcom 5.6 bug] kABI whitelist request for bnx2i</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/559815" id="559815">ACPI _SDD failed (AE 0x5) messages on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/560540" id="560540">Reserve PNP enumerated system board iomem resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/560870" id="560870">Update Neighbor Cache when IPv6 RA is received on a router</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/562220" id="562220">IP PACKET DOES NOT TRANSMIT USING RAW SOCKETS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/563271" id="563271">ITE it887x chipset serial ports don't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/564249" id="564249">[LSI 5.6 feat] update megaraid_sas to version 4.31</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/565560" id="565560">[5.6 FEAT] KVM network performance: Defer skb allocation in virtio-net</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/565973" id="565973">[EMC 5.6 bug] security and PSF update patch for EMC CKD ioctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/565974" id="565974">[5.6 FEAT] NFSv4 remove does not wait for close. Silly rename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/566104" id="566104">route: BUG at include/linux/timer.h:82 (call from rt_secret_rebuild_oneshot)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/566144" id="566144">Loading NAT module with/without rules affects ping behaviour</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/566767" id="566767">[Emulex 5.6 bug] kABI whitelist request for lpfc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567092" id="567092">possible recursive locking of inode by nfsd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567428" id="567428">[QLogic 5.6 FEAT] Update qla2xxx driver to version 8.03.01.05.05.06-k</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567444" id="567444">RHEL5.6: cxgb3i driver update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567462" id="567462">[Broadcom 5.6 feat] Update tg3 to version 3.108+ and add 5718 B0, 5719 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567479" id="567479">fasync_helper patch causing problems with GPFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567604" id="567604">[Regression] bonding: 802.3ad problems with link detection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/568111" id="568111">[Cisco 5.6 FEAT] Update enic driver to version 1.4.1.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/568601" id="568601">[Broadcom 5.6 FEAT] Update bnx2 to 2.0.8+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/568606" id="568606">[Broadcom 5.6 FEAT] Update bnx2i driver and add 57712 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569106" id="569106">netconsole fails with tg3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569342" id="569342">[5.4] nfsd dereferences uninitialized list head on error exit in nfsd4_list_rec_dir()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569643" id="569643">[Emulex 5.6 feat] Add be2iscsi driver for BE3 asic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569654" id="569654">boot hangs if scsi read capacity fails on faulty non system drive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570044" id="570044">kernel panic when rmmod and insmod rpcsec_gss_krb5 module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570091" id="570091">cpu flags missing from /proc/cpuinfo</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570491" id="570491">vmalloc ENOMEM caused by iptables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570604" id="570604">X can't get signals with DRI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570610" id="570610">[RHEL5]: Add thread_siblings_list to /sys</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570645" id="570645">[RHEL5] bonding mode 0 doesn't resend IGMP after a failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570681" id="570681">REGRESSION: Fix iscsi failover time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/570824" id="570824">Timedrift on VM with pv_clock enabled, causing system hangs and sporadic time behaviour</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/571518" id="571518">revalidate dentries provided by LAST_BIND symlinks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/571735" id="571735">backports of virtio_blk barrier support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/571862" id="571862">[Emulex 5.6 feat] Update lpfc driver to version 8.2.0.73.1p and include BE3 asic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/571864" id="571864">RHEL5: coretemp: fix cpu model output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/572004" id="572004">[LSI 5.6 FEAT] Update 3w-9xxx driver to v2.26.08.007-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/572011" id="572011">[LSI 5.6 FEAT] Add 3w-sas driver and update to v3.26.00.028-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/572285" id="572285">Add /sys/devices/system/node/nodeX/cpulist files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/572930" id="572930">Bad ext4 sync performance on 16 TB GPT partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/573106" id="573106">[Stratus 5.6 bug] task md0_resync:18061 blocked for more than 120 seconds</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/573185" id="573185">large storage data corruption on 32 bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/573652" id="573652">Regression: AUTH_SYS cannot be requested using the 'sec=sys' export option.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/573771" id="573771">should set ISVM bit (ECX:31) for CPUID leaf 0x00000001</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/574285" id="574285">25% performance regression of concurrent O_DIRECT writes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/574557" id="574557">[Cisco 5.6 bug] kABI request for fcoe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/574913" id="574913">memory leak when ipv6 interface disabled in sysctl.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/575309" id="575309">Kernel panic - not syncing: IO-APIC + timer doesn't work!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/575817" id="575817">nfsv4 hangs -- client/server deadlock between commit and delegation return</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/576246" id="576246">missing power_meter release() function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/576709" id="576709">[Cisco 5.6 bug] fnic: flush Tx queue bug fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/577182" id="577182">vxge: not enough MMIO resources for SR-IOV error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578005" id="578005">[Broadcom 5.6 bug] Cannot login to iSCSI target when bnx2i is loaded last</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578259" id="578259">Network throughput drops seriously on DomU to DomU node traffic on RHEL5.3 Xen when NIC performs RSC.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578261" id="578261">[5.5] SCTP: Check if the file structure is valid before checking the non-blocking flag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578492" id="578492">e1000_clean_tx_irq: Detected Tx Unit Hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578531" id="578531">[RHEL5.5] soft lockup on vlan with bonding in balance-alb mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578905" id="578905">RHEL 5.3 on DL585 G6: testing NMI watchdog fails on bootup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/580699" id="580699">hwmon: (coretemp) Get TjMax value from MSR for i series CPUs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/581396" id="581396">[PATCH][RHEL5.5] Fix Time drift on KVM x86_64 RHEL5.5 Guest using PV clock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/581654" id="581654">RTL-8169 Gigatit Ethernet network devices mac address changes after soft reboot.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/581933" id="581933">pci_mmcfg_init() making some of main memory uncacheable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582003" id="582003">Enable LED support in iwlagn and iwl3945 drivers (IWLWIFI_LEDS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582237" id="582237">"hung_task" feature port is incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582321" id="582321">VFS: Busy inodes after unmount issue.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582367" id="582367">implement dev_disable_lro for RHEL5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582435" id="582435">[Stratus 5.6 bug] Circular lock dep warning on cfq_exit_lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582722" id="582722">TCP socket premature timeout with FRTO and TSO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582886" id="582886">The assigned VF cannot be found in PV guest.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/583673" id="583673">set-cpu_llc_id-on-amd-cpus patch: undefined variable 'cpu' in in amd_detect_cmp()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/583767" id="583767">dev_set_name() undefined in net/wireless/cfg80211.ko in some cases</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/584412" id="584412">transmission stops when tap does not consume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/584679" id="584679">The kvm clock couldn't go back after stop/continue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/585431" id="585431">Add log message for unhandled sense error REPORTED_LUNS_DATA_CHANGED</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/586482" id="586482">ATIIXP IDE driver reuses ide_lock unsafely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/588015" id="588015">x86_64 host on Nehalem-EX machines will panic when installing a 4.8 GA kvm guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/588599" id="588599">Kernel BUG at fs/ext3/super.c:425</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590760" id="590760">compiling a xen config produces lots of pud_present warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590763" id="590763">PG_error bit is never cleared, even when a fresh I/O to the page succeeds</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590864" id="590864">Unkillable processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/591548" id="591548">netback does not properly get to the Connected state after it's been Closed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/591674" id="591674">[Emulex 5.6 bug] Update lpfc driver to version 8.2.0.76.1p</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592322" id="592322">[RHEL 5] Errors when Accessing iSCSI luns via iSER - timing out command</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592908" id="592908">Memory leak when nfs shares are mounted with option "nolock"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592961" id="592961">ext3: fsync() does not flush disk caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/593040" id="593040">TCP: avoid to send keepalive probes if receiving data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/593801" id="593801">[RHEL5.5] TCP bandwidth problems with TPA and bnx2x cards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/593862" id="593862">[RHEL5.5] Self-test using 'ethtool -t ethX' fails with "Cannot test: Operation not supported"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/594404" id="594404">[RHEL 5.5] vxge: unable to create VLAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/594546" id="594546">[Intel 5.6 Bug] CPU synchronization required when doing MTRR register update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/594635" id="594635">kernel: security: testing the wrong variable in create_by_name() [rhel-5.6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/595397" id="595397">GFS2: stuck in inode wait, no glocks stuck</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/595548" id="595548">[Broadcom 5.6 bug] bnx2i: MTU change does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/595862" id="595862">[Broadcom 5.6 bug] cnic: Panic in cnic_iscsi_nl_msg_recv()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/596548" id="596548">dcache unused accounting problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/596626" id="596626">Create reliable implementation of cancel_(delayed)_work_sync() in RHEL5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/597143" id="597143">[LSI 5.6 bug] kABI request for mptsas, mpt2sas</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/597334" id="597334">reg_regdb_search_lock calls kmalloc while holding spinlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598946" id="598946">[NetApp 5.6 bug] QLogic FC firmware errors seen on RHEL 5.5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/599295" id="599295">Significant MSI performance issue due to redundant interrupt masking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/600387" id="600387">gfs2 kernel - Better error reporting when mounting a gfs fs without enough journals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/601692" id="601692">RFE virtio balloon driver does not include extended memory statistics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/601800" id="601800">NFS-over-GFS out-of-order GETATTR Reply causes corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/602402" id="602402">bnx2x panic dumps with multiple interfaces enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/603706" id="603706">cifs: busy file renames across directories should fail with error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/603806" id="603806">[Emulex 5.6 bug] Update lpfc driver to version 8.2.0.77</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/604044" id="604044">NFS4 breaks when server returns NFS4ERR_FILE_OPEN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/604779" id="604779">Page out activity when there is no current VM load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605259" id="605259">tcp: sending reset to the already closed socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605265" id="605265">kernel bug in cfq merge logic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605305" id="605305">need to backport 2e3219b5c8a2e44e0b83ae6e04f52f20a82ac0f2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605697" id="605697">[RHEL 5.5] 32-bit pvhvm guest on 64-bit host crash w/xm mem-set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605720" id="605720">[RHEL 5.5] nfs: fix compatibility with hpux clients</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605816" id="605816">[RHEL 5.6] move Tausworthe net_random generator to lib/random32</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606851" id="606851">Wrong /proc/cpuinfo for Pentium D reported on RHEL 4.8 (only x86_64) and RHEL 5.5 (both i386 and x86_64)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607443" id="607443">soft lockup inside rhel5 guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/608641" id="608641">vegas and veno possible division by zero bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/608801" id="608801">[Emulex 5.6 bug] be2iscsi: IO stalls if any SGE  size=65536</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/609668" id="609668">kswapd hung in D state with fragmented memory and large order allocations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/610234" id="610234">[5u6] Bonding in ALB mode sends ARP in loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/611938" id="611938">[RHEL5u3] System panic at sunrpc xprt_autoclose()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/612212" id="612212">igb: typo in igb aer code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613134" id="613134">[QLogic 5.6 FEAT] Add P3+ AER support to qla2xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613187" id="613187">xen Windows 2008 guest crashes on RHEL 5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613667" id="613667">always print the number of triggered NMI during test at boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613780" id="613780">[RHEL 5.5] igb driver re-order UDP packets when multi-queue is enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/614281" id="614281">[QLogic 5.6 FEAT] Feature Updates and Bug Fixes for qlcnic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/614957" id="614957">ext4: mount error path corrupts slab memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/615227" id="615227">fix oops in clusterip_seq_stop when memory allocation fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/615229" id="615229">fix oops in dl_seq_stop when memory allocation fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616512" id="616512">[Emulex 5.6 feat] Update be2net to version 2.102.404r</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617024" id="617024">[Broadcom 5.6 FEAT] bnx2: add AER support.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617268" id="617268">kernel crash in br_nf_pre_routing_finish</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617690" id="617690">ext4 and xfs wrong data returned on read after write if file size was changed with ftruncate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618075" id="618075">RHEL5.5 boot fail with IDE controller enabled on Cobia</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618114" id="618114">Kernel panic on reading from /proc/bus/pci/XX/YY while hot-removing the device.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618512" id="618512">[QLogic 5.6] kABI whitelist request for qla4xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619070" id="619070">802.3ad link aggregation won't work with newer (2.6.194-8.1.el5) kernel and ixgbe driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619112" id="619112">CIFS mount to samba3x share shows differing ownership on sequential stat() calls to same file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619361" id="619361">[NetApp 5.6 bug] SCSI ALUA handler fails to handle ALUA transitioning properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619767" id="619767">Update cnic to 2.1.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619814" id="619814">[Qlogic 5.6 bug] qla2xxx: Back port of upstream fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619917" id="619917">[Emulex 5.6 feat] Update lpfc driver to version 8.2.0.80</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/620037" id="620037">virtio-serial - need to back port guest driver to RHEL 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/620502" id="620502">[NetApp 5.6 bug] RHEL NFS clients disconnected from NetApp NFSv4 shares with: v4 server returned a bad sequence-id error!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/620508" id="620508">system crashes due to corrupt net_device_wrapper structure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/621105" id="621105">backport wireless upstream 2.6.32.18 fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/621280" id="621280">[5u5] bonding: fix a race condition in calls to slave MII ioctls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622024" id="622024">64-bit kernel unable to oprofile 32-bit processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622559" id="622559">libata: fix suspend/resume for ATA SEMB devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623519" id="623519">ENOPERM when reading /proc/sys/vm/mmap_min_addr</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623595" id="623595">move iscsi/iser to passthrough mode, fix functioning and failover time under DM multipath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623675" id="623675">[QLogic 5.6 feat] qla4xxx: Update driver to 5.02.03.00.05.06-d1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624598" id="624598">Win7 and Windows 2008 R2 xen guests with multiple vcpus can't restart</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624710" id="624710">[QLogic 5.6 FEAT] qla4xxx: Add PCIe AER support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624862" id="624862">[rhel5.6] XFS incorrectly validates inodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625061" id="625061">igb doesn't see link status changes on 82580 NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625079" id="625079">[QLogic 5.6 bug] netxen: Fix enabling VLAN TSO/LSO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625084" id="625084">[QLogic 5.6 bug] qlcnic: Fix netdev features and other fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625688" id="625688">CVE-2010-4243 kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625841" id="625841">lpfc ioctl crash in lpfc_nlp_put()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625902" id="625902">[Xen] backport NMI injection for HVM guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625903" id="625903">[Xen] backport hardware task switching for HVM guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626018" id="626018">Allow using crc32c hardware accelerated engine on Intel Nehalem processor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626566" id="626566">IPR driver needs fixes to support the new Cubic-R adapter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626963" id="626963">AIO uses igrab in the submission path, which causes undue lock contention</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627612" id="627612">[QLogic 5.6 BUG] qla2xxx: Correctly displaying the link state for disconnected port.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627836" id="627836">retry rather than fastfail DID_REQUEUE scsi errors with dm-multipath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627974" id="627974">Scheduling while atomic when removing slave tg3 interface from bonding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628828" id="628828">Fix hot-unplug handling of virtio-console ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628831" id="628831">Enable NAPI for forcedeth driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629081" id="629081">Bug 466441 reintroduced in kernel 2.6.18-194.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629176" id="629176">kernel: Problem with execve(2) reintroduced [rhel-5.6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629457" id="629457">vlan: control vlan device TSO status with ethtool</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629626" id="629626">groups_search() cannot handle large gid correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629634" id="629634">add pr_*(), netdev_*(), netif_*() printk helper macros</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629638" id="629638">kernel panic in devinet_sysctl_forward when changing the /proc/sys/net/ipv4/conf/eth*/forwarding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629761" id="629761">[RHEL 5.5] e100/e1000*/igb*/ixgb*: Add missing read memory barrier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629773" id="629773">HVM guest w/ UP and PV driver hangs after live migration or suspend/resume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630124" id="630124">Detect and recover from cxgb3 adapter parity errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630129" id="630129">[RHEL5 IA64 XEN] netfront driver: alloc_dev: Private data too big.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630563" id="630563">kernel: additional stack guard patches [rhel-5.6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630680" id="630680">[Emulex 5.6 feat] Update be2net to version 2.102.453r</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631963" id="631963">[Broadcom 5.6 bug] tg3: 5717 / 57765 / 5719 devices leak memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632057" id="632057">[Broadcom 5.6 bug] bnx2: Remove some unnecessary smp_mb() in tx fast path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633149" id="633149">CVE-2010-3296 kernel: drivers/net/cxgb3/cxgb3_main.c reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633388" id="633388">sfc: creates too many queues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634320" id="634320">[Broadcom 5.6 feat] tg3: Re-enable 5717 B0 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634325" id="634325">[Broadcom 5.6 bug] tg3: Incorrect FW version displayed and FW handshake update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635027" id="635027">[RHEL5.6] Verify that driver version strings for updated network drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635782" id="635782">Add dirty_background_bytes and dirty_bytes sysctls to RHEL 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636020" id="636020">PATCH: virtio_console: Fix poll blocking even though there is data to read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636046" id="636046">Disallow 0-sized writes to virtio ports to go through to host (leading to VM crash)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636053" id="636053">read from virtio-serial returns if the host side is not connect to pipe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636100" id="636100">TPM driver is not enabled in kernel-xen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636760" id="636760">TPM driver complains about IRQ mismatches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637194" id="637194">[Qlogic 5.6 bug] qlcnic: fix kernel NULL pointer dereference __qlcnic_shutdown+0xe/0x8a</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637764" id="637764">Bonded interface doesn't issue IGMP report (join) on slave interface during failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637826" id="637826">belkin usb nic card fails - module catc.ko</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638082" id="638082">Backport HVMOP_get_time hypercall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639028" id="639028">[Emulex 5.6 feat] Update lpfc driver to version 8.2.0.85</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640026" id="640026">bnx2 adapter periodically dropping received packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640586" id="640586">sata_sil24 - add support for Adaptec 1225SA RAID eSATA controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641086" id="641086">mpt2sas driver update causes boot failure with Dell PERC H200 SAS HBA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641193" id="641193">[NetApp 5.6 bug] regression: allow offlined devs to be set to running</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643080" id="643080">tasks blocked after putting Nehalem CPU offline</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643165" id="643165">GFS2: BUG_ON kernel panic in gfs2_glock_hold on 2.6.18-226</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643254" id="643254">[QLogic 5.6 bug] kdump: netxen_nic doesn't work in network dumping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643426" id="643426">Stack size mapping is decreased through mlock/munlock call</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643707" id="643707">[kdump] soft lockup occurs when nmi watchdog lockup is being triggered</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644129" id="644129">Kernel build from source leaves kabideps file droppings in _tmppath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644136" id="644136">[QLogic 5.6 bug] qla2xxx: Fix incorrect test for zero</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644438" id="644438">bnx2: Out of order arrival of UDP packets in application</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644726" id="644726">panic in find_ge_pid() due to race between lseek() and readdir() on /proc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644735" id="644735">writing to a virtio serial port while no one is listening on the host side hangs the guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644863" id="644863">[NetApp 5.6 bug] qla2xxx: Kernel panic on qla24xx_queuecommand</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644879" id="644879">RHEL5.6 Include DL580 G7 in bfsort whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645284" id="645284">modprobe igb max_vfs>7(Max support is 7) leads to host reboot in loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645881" id="645881">[Emulex 5.6 feat] Update lpfc driver to version 8.2.0.86</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646708" id="646708">regression: bnx2i driver returns garbage in host param callout and could oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647259" id="647259">[Emulex 5.6 bug] Update be2net to version 2.102.512r</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647297" id="647297">Direct IO write to a file on an nfs mount does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648656" id="648656">CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648658" id="648658">CVE-2010-4073 kernel: ipc/compat*.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648660" id="648660">CVE-2010-4075 kernel: drivers/serial/serial_core.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648669" id="648669">CVE-2010-4080 kernel: drivers/sound/pci/rme9652/hdsp.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648670" id="648670">CVE-2010-4081 kernel: drivers/sound/pci/rme9652/hdspm.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649489" id="649489">[Emulex 5.6 bug] Update lpfc driver to version 8.2.0.87</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649717" id="649717">CVE-2010-3877 kernel: net/tipc/socket.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651287" id="651287">[Broadcom 5.6 bug] cnic: Panic in uio_release()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651698" id="651698">CVE-2010-4158 kernel: socket filters infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651869" id="651869">probe-remove loop of i7core_edac module causes oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652165" id="652165">ALSA: fix sysfs related issues (modules cannot be reloaded) and mutex problem in OSS mixer emulation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652279" id="652279">[5.6 FEAT] POWER7 added to Aux Vextor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653250" id="653250">kernel: restrict unprivileged access to kernel syslog [rhel-5.6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653262" id="653262">[5.6 Regression] network is lost after balloon-up fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653501" id="653501">netback tries to balloon up even if front-end doesn't do flipping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653991" id="653991">[Broadcom 5.6 bug] bnx2i: add upstream bug fixes to 2.6.2.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654420" id="654420">[QLogic 5.6 bug] qlge: Update driver to 1.0.0.27</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654948" id="654948">RHEL5.6 : 10Gb network card (AD144 &amp;AD385)will  be  missing  in installation and can not be drived in system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655119" id="655119">[Emulex 5.6 bug] Update lpfc driver to version 8.2.0.87.1p</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655623" id="655623">CVE-2010-4238 kernel: Xen Dom0 crash with Windows 2008 R2 64bit DomU + GPLPV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656008" id="656008">[Qlogic 5.6 bug] qlcnic: Fix kdump issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657097" id="657097">[Broadcom 5.6 bug] tg3: Fix 5719 bugs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658155" id="658155">CVE-2010-4255 xen: 64-bit PV xen guest can crash host by accessing hypervisor per-domain memory area</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658434" id="658434">forcedeth driver panics while booting debug kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658801" id="658801">[REG][5.6] igb never counts up the number of tx packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659571" id="659571">CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-5.6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660188" id="660188">CVE-2010-4263 kernel: igb panics when receiving tag vlan packet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660506" id="660506">[Broadcom 5.6 bug] tg3: Increase tx jumbo bd flag threshold</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660580" id="660580">[REG][5.6] kernel panic occurs by writing a file on optional mount "sync/noac" of NFSv4.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661182" id="661182">CVE-2010-4343 kernel: bfa driver sysfs crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661393" id="661393">[IPv6] a specific route is ignored if the default gateway is reachable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663509" id="663509">[Broadcom 5.6 bug] bnx2: calling pci_map_page() twice in tx path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663853" id="663853">[REG][5.6] kernel panic occurs by reading an empty file on optional mount "sync/noac" of NFSv4.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017004" comment="kernel-headers is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017002" comment="kernel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017024" comment="kernel-doc is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017022" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017008" comment="kernel-devel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017012" comment="kernel-debug is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017016" comment="kernel-kdump is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017010" comment="kernel-xen-devel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017006" comment="kernel-debug-devel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017020" comment="kernel-PAE is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017018" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110017014" comment="kernel-xen is earlier than 0:2.6.18-238.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110025" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0025: gcc security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0025.html" />
          <reference source="CVE" ref_id="CVE-2010-0831" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0831.html" />
          <reference source="CVE" ref_id="CVE-2010-2322" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2322.html" />
    
    <description>The gcc packages include C, C++, Java, Fortran, Objective C, and Ada 95 GNU
compilers, along with related support libraries. The libgcj package
provides fastjar, an archive tool for Java Archive (JAR) files.

Two directory traversal flaws were found in the way fastjar extracted JAR
archive files. If a local, unsuspecting user extracted a specially-crafted
JAR file, it could cause fastjar to overwrite arbitrary files writable by
the user running fastjar. (CVE-2010-0831, CVE-2010-2322)

This update also fixes the following bugs:

* The option -print-multi-os-directory in the gcc --help output is not in
the gcc(1) man page. This update applies an upstream patch to amend this.
(BZ#529659)

* An internal assertion in the compiler tried to check that a C++ static
data member is external which resulted in errors. This was because when the
compiler optimizes C++ anonymous namespaces the declarations were no longer
marked external as everything on anonymous namespaces is local to the
current translation. This update corrects the assertion to resolve this
issue. (BZ#503565, BZ#508735, BZ#582682)

* Attempting to compile certain .cpp files could have resulted in an
internal compiler error. This update resolves this issue. (BZ#527510)

* PrintServiceLookup.lookupPrintServices with an appropriate DocFlavor
failed to return a list of printers under gcj. This update includes a
backported patch to correct this bug in the printer lookup service.
(BZ#578382)

* GCC would not build against xulrunner-devel-1.9.2. This update removes
gcjwebplugin from the GCC RPM. (BZ#596097)

* When a SystemTap generated kernel module was compiled, gcc reported an
internal compiler error and gets a segmentation fault. This update applies
a patch that, instead of crashing, assumes it can point to anything.
(BZ#605803)

* There was a performance issue with libstdc++ regarding all objects
derived from or using std::streambuf because of lock contention between
threads. This patch ensures reload uses the same value from _S_global for
the comparison, _M_add_reference () and _M_impl member of the class.
(BZ#635708)

All gcc users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-13" />
        <updated date="2011-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0831.html">CVE-2010-0831</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2322.html">CVE-2010-2322</cve>
                <bugzilla href="http://bugzilla.redhat.com/503565" id="503565">libtorrent-rasterbar won't compile, internal compiler error: in make_rtl_for_nonlocal_decl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508735" id="508735">internal gcc error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527510" id="527510">Internal compiler error from gcc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529659" id="529659">Option -print-multi-os-directory is not described in man page gcc(1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578382" id="578382">PrintServiceLookup.lookupPrintServices(DocFlavor.SERVICE_FORMATTED.PAGEABLE, null)   in a simple test java program fails to list printers when run with gcj - Any conventional JRE seems to work that I have tested</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582682" id="582682">internal compiler error: in make_rtl_for_nonlocal_decl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/594497" id="594497">CVE-2010-0831 CVE-2010-2322 fastjar: directory traversal vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/596097" id="596097">gcc doesn't build against xulrunner-devel-1.9.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605803" id="605803">gcc gets an internal compiler error when compiling a kernel module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635708" id="635708">Huge performance problem with libstdc++ and multithread applications</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025034" comment="libgcj-src is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025035" comment="libgcj-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025032" comment="gcc-objc++ is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025033" comment="gcc-objc++ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025022" comment="libgfortran is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025023" comment="libgfortran is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025026" comment="libmudflap is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025027" comment="libmudflap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025024" comment="gcc-gfortran is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025025" comment="gcc-gfortran is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025012" comment="libgcc is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025013" comment="libgcc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025008" comment="libgcj-devel is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025009" comment="libgcj-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025030" comment="cpp is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025031" comment="cpp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025038" comment="gcc-gnat is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025039" comment="gcc-gnat is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025020" comment="libstdc++ is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025021" comment="libstdc++ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025016" comment="libmudflap-devel is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025017" comment="libmudflap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025028" comment="gcc-objc is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025029" comment="gcc-objc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025010" comment="gcc-c++ is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025011" comment="gcc-c++ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025002" comment="gcc is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025003" comment="gcc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025006" comment="gcc-java is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025007" comment="gcc-java is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025036" comment="libgnat is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025037" comment="libgnat is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025014" comment="libgcj is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025015" comment="libgcj is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025004" comment="libstdc++-devel is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025005" comment="libstdc++-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110025018" comment="libobjc is earlier than 0:4.1.2-50.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110025019" comment="libobjc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110027" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0027: python security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0027-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0027.html" />
          <reference source="CVE" ref_id="CVE-2008-5983" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5983.html" />
          <reference source="CVE" ref_id="CVE-2009-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4134.html" />
          <reference source="CVE" ref_id="CVE-2010-1449" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1449.html" />
          <reference source="CVE" ref_id="CVE-2010-1450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1450.html" />
          <reference source="CVE" ref_id="CVE-2010-1634" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1634.html" />
          <reference source="CVE" ref_id="CVE-2010-2089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

It was found that many applications embedding the Python interpreter did
not specify a valid full path to the script or application when calling the
PySys_SetArgv API function, which could result in the addition of the
current working directory to the module search path (sys.path). A local
attacker able to trick a victim into running such an application in an
attacker-controlled directory could use this flaw to execute code with the
victim's privileges. This update adds the PySys_SetArgvEx API. Developers
can modify their applications to use this new API, which sets sys.argv
without modifying sys.path. (CVE-2008-5983)

Multiple flaws were found in the Python rgbimg module. If an application
written in Python was using the rgbimg module and loaded a
specially-crafted SGI image file, it could cause the application to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2009-4134, CVE-2010-1449, CVE-2010-1450)

Multiple flaws were found in the Python audioop module. Supplying certain
inputs could cause the audioop module to crash or, possibly, execute
arbitrary code. (CVE-2010-1634, CVE-2010-2089)

This update also fixes the following bugs:

* When starting a child process from the subprocess module in Python 2.4,
the parent process could leak file descriptors if an error occurred. This
update resolves the issue. (BZ#609017)

* Prior to Python 2.7, programs that used "ulimit -n" to enable
communication with large numbers of subprocesses could still monitor only
1024 file descriptors at a time, which caused an exception:

  ValueError: filedescriptor out of range in select()

This was due to the subprocess module using the "select" system call. The
module now uses the "poll" system call, removing this limitation.
(BZ#609020)

* Prior to Python 2.5, the tarfile module failed to unpack tar files if the
path was longer than 100 characters. This update backports the tarfile
module from Python 2.5 and the issue no longer occurs. (BZ#263401)

* The email module incorrectly implemented the logic for obtaining
attachment file names: the get_filename() fallback for using the deprecated
"name" parameter of the "Content-Type" header erroneously used the
"Content-Disposition" header. This update backports a fix from Python 2.6,
which resolves this issue. (BZ#644147)

* Prior to version 2.5, Python's optimized memory allocator never released
memory back to the system. The memory usage of a long-running Python
process would resemble a "high-water mark". This update backports a fix
from Python 2.5a1, which frees unused arenas, and adds a non-standard
sys._debugmallocstats() function, which prints diagnostic information to
stderr. Finally, when running under Valgrind, the optimized allocator is
deactivated, to allow more convenient debugging of Python memory usage
issues. (BZ#569093)

* The urllib and urllib2 modules ignored the no_proxy variable, which could
lead to programs such as "yum" erroneously accessing a proxy server for
URLs covered by a "no_proxy" exclusion. This update backports fixes of
urllib and urllib2, which respect the "no_proxy" variable, which fixes
these issues. (BZ#549372)

As well, this update adds the following enhancements:

* This update introduces a new python-libs package, subsuming the majority
of the content of the core python package. This makes both 32-bit and
64-bit Python libraries available on PowerPC systems. (BZ#625372)

* The python-libs.i386 package is now available for 64-bit Itanium with the
32-bit Itanium compatibility mode. (BZ#644761)

All Python users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-13" />
        <updated date="2011-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5983.html">CVE-2008-5983</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4134.html">CVE-2009-4134</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1449.html">CVE-2010-1449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1450.html">CVE-2010-1450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1634.html">CVE-2010-1634</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2089.html">CVE-2010-2089</cve>
                <bugzilla href="http://bugzilla.redhat.com/482814" id="482814">CVE-2008-5983 python: untrusted python modules search path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/541698" id="541698">CVE-2009-4134 CVE-2010-1449 CVE-2010-1450 python: rgbimg: multiple security issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569093" id="569093">Python 2.4's arena allocator does not release memory back to the system, leading to "high-water mark" memory usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590690" id="590690">CVE-2010-1634 python: audioop: incorrect integer overflow checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598197" id="598197">CVE-2010-2089 Python: Memory corruption in audioop module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/609017" id="609017">subprocess leaves open fds on construction error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/609020" id="609020">subprocess fails in select when descriptors are large</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625372" id="625372">split python-libs subpackage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644147" id="644147">Patch for get_filename in email.message when content-disposition is missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644761" id="644761">python-libs conflict on ia64 compatlayer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110027008" comment="python-devel is earlier than 0:2.4.3-43.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027009" comment="python-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110027004" comment="python-libs is earlier than 0:2.4.3-43.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027005" comment="python-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110027010" comment="tkinter is earlier than 0:2.4.3-43.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027011" comment="tkinter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110027002" comment="python is earlier than 0:2.4.3-43.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027003" comment="python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110027006" comment="python-tools is earlier than 0:2.4.3-43.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027007" comment="python-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110028" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0028: kvm security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0028-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0028.html" />
          <reference source="CVE" ref_id="CVE-2010-4525" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4525.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

A data structure field in kvm_vcpu_ioctl_x86_get_vcpu_events() in QEMU-KVM
was not initialized properly before being copied to user-space. A
privileged host user with access to "/dev/kvm" could use this flaw to leak
kernel stack memory to user-space. (CVE-2010-4525)

Red Hat would like to thank Stephan Mueller of atsec information security
for reporting this issue.

These updated packages also fix several bugs. Documentation for these bug
fixes will be available shortly in the "kvm" section of the Red Hat
Enterprise Linux 5.6 Technical Notes, linked to in the References.

All KVM users should upgrade to these updated packages, which resolve this
issue as well as fixing the bugs noted in the Technical Notes. Note: The
procedure in the Solution section must be performed before this update will
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-13" />
        <updated date="2011-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4525.html">CVE-2010-4525</cve>
                <bugzilla href="http://bugzilla.redhat.com/503118" id="503118">kvm doesn't run with older libgcrypt, but doesn't have a RPM dependency for it</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510630" id="510630">-drive arg has no way to request a read only disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513765" id="513765">Large guest ( 256G RAM + 16 vcpu ) hang during live migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514578" id="514578">kvm-qemu-img subpackage has dependency on qspice-libs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517565" id="517565">build KVM modules for kernel-debug too</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517814" id="517814">Caps Lock the key's appearance  of guest is not synchronous as host's --view kvm with vnc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520572" id="520572">SR-IOV -- Guest exit and host hang on if boot VM with 8 VFs assigned</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521247" id="521247">emulated pcnet nic in qemu-kvm has wrong PCI subsystem ID for Windows XP driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533078" id="533078">use native smp_call_function_many/single functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539642" id="539642">use native pci_get_bus_and_slot function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/542954" id="542954">Guest suffers kernel panic when save snapshot then restart guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/555727" id="555727">Time drift in win2k3-64bit and win2k8-64bit smp guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569743" id="569743">Change vnc password caused 'Segmentation fault'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/572825" id="572825">qcow2 image corruption when using cache=writeback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/574621" id="574621">Linux pvmmu guests (FC11, FC12, etc) crash on boot on AMD hosts with NPT disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/575585" id="575585">memory reported as used (by SwapCache and by Cache) though no process holds it.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/580410" id="580410">Failed to install kvm for failed dependencies: ksym</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/580637" id="580637">Incorrect russian vnc keymap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/582038" id="582038">backport EPT accessed bit emulation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/583947" id="583947">Guest aborted when make guest stop on write error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/587604" id="587604">Qcow2 snapshot got corruption after commit using block device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/587605" id="587605">Failed to re-base qcow2 snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/588251" id="588251">kvm spinning updating a guest pte, unkillable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/588878" id="588878">Rebooting a kernel with kvmclock enabled, into a kernel with kvmclock disabled, causes random crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/589017" id="589017">[rhel5.5] [kvm] dead lock in qemu during off-line migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592021" id="592021">race condition in pvclock wallclock calculation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598042" id="598042">virtio-blk: Avoid zeroing every request structure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598488" id="598488">qcow2 corruption bug in refcount table growth</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/601494" id="601494">qemu-io: No permission to write image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/603026" id="603026">CPU save version is now 9, but the format is _very_ different from non-RHEL5 version 9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605701" id="605701">Backport qcow2 fixes to RHEL 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606238" id="606238">Virtio: Transfer file caused guest in same vlan abnormally quit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606394" id="606394">[kvm] debug-info missing from kvm-qemu-img-83-164.el5_5.12</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606434" id="606434">[kvm] segmentation fault when running qemu-img check on faulty image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606651" id="606651">[kvm] qemu image check returns cluster errors when using virtIO block (thinly provisioned) during e_no_space events (along with EIO errors)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/606953" id="606953">fork causes trouble for vcpu threads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/611982" id="611982">Monitor doesn't check for 'change' command failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619268" id="619268">rmmod kvm modules cause host kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627343" id="627343">husb: ctrl buffer too small error received for passthrough usb device, fixed upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629333" id="629333">fix build against kernel-devel-2.6.18-214.el5.x86_64: (cancel_work_sync() conflict)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629334" id="629334">use native cancel_work_sync() function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632707" id="632707">fix kvm build warnings and enable -Werror</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637267" id="637267">spec file changes for kmod + kernel-devel build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640949" id="640949">Can not commit copy-on-write image's data to raw backing-image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641823" id="641823">kmod-kvm has unresolved deps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643272" id="643272">unresolved deps in kmod-kvm-debug-83-205.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643317" id="643317">"sendkey ctrl-alt-delete" don't work via VNC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645798" id="645798">Add drive readonly option to help output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648328" id="648328">TCP checksum overflows in qemu's e1000 emulation code when TSO is enabled in guest OS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651715" id="651715">qemu-kvm aborted when installing the driver for the newly hotplugged rtl8139 nic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655990" id="655990">clock drift when migrating a guest between mis-matched CPU clock speed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665470" id="665470">CVE-2010-4525 kvm: x86: zero kvm_vcpu_events->interrupt.pad infoleak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110028004" comment="kvm-qemu-img is earlier than 0:83-224.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110028005" comment="kvm-qemu-img is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110028002" comment="kvm is earlier than 0:83-224.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110028003" comment="kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110028008" comment="kmod-kvm is earlier than 0:83-224.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110028009" comment="kmod-kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110028006" comment="kmod-kvm-debug is earlier than 0:83-224.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110028007" comment="kmod-kvm-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110028010" comment="kvm-tools is earlier than 0:83-224.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110028011" comment="kvm-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110152" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0152: java-1.4.2-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0152.html" />
          <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html" />
          <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html" />
    
    <description>The IBM 1.4.2 SR13-FP8 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes two vulnerabilities in the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit. Detailed vulnerability
descriptions are linked from the IBM "Security alerts" page, listed in the
References section. (CVE-2010-1321, CVE-2010-3574)

Note: The RHSA-2010:0935 java-1.4.2-ibm update did not, unlike the erratum
text stated, provide fixes for the above issues.

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP8 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-17" />
        <updated date="2011-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1321.html">CVE-2010-1321</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3574.html">CVE-2010-3574</cve>
                <bugzilla href="http://bugzilla.redhat.com/582466" id="582466">CVE-2010-1321 krb5: null pointer dereference in GSS-API library leads to DoS (MITKRB5-SA-2010-005)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642215" id="642215">CVE-2010-3574 OpenJDK HttpURLConnection incomplete TRACE permission check (6981426)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152012" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110152008" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110153" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0153: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0153-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0153.html" />
          <reference source="CVE" ref_id="CVE-2010-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4345.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on UNIX systems connected to the Internet.

A privilege escalation flaw was discovered in Exim. If an attacker were
able to gain access to the "exim" user, they could cause Exim to execute
arbitrary commands as the root user. (CVE-2010-4345)

This update adds a new configuration file, "/etc/exim/trusted-configs". To
prevent Exim from running arbitrary commands as root, Exim will now drop
privileges when run with a configuration file not listed as trusted. This
could break backwards compatibility with some Exim configurations, as the
trusted-configs file only trusts "/etc/exim/exim.conf" and
"/etc/exim/exim4.conf" by default. If you are using a configuration file
not listed in the new trusted-configs file, you will need to add it
manually.

Additionally, Exim will no longer allow a user to execute exim as root with
the -D command line option to override macro definitions. All macro
definitions that require root permissions must now reside in a trusted
configuration file.

Users of Exim are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the exim daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-17" />
        <updated date="2011-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4345.html">CVE-2010-4345</cve>
                <bugzilla href="http://bugzilla.redhat.com/662012" id="662012">CVE-2010-4345 exim privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153006" comment="exim-mon is earlier than 0:4.63-5.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153007" comment="exim-mon is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153002" comment="exim is earlier than 0:4.63-5.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153003" comment="exim is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153004" comment="exim-sa is earlier than 0:4.63-5.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153005" comment="exim-sa is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153015" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153016" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153013" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153014" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153009" comment="exim is earlier than 0:4.43-1.RHEL4.5.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153010" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110153011" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110153012" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110154" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0154: hplip security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0154.html" />
          <reference source="CVE" ref_id="CVE-2010-4267" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4267.html" />
    
    <description>Hewlett-Packard Linux Imaging and Printing (HPLIP) provides drivers for
Hewlett-Packard printers and multifunction peripherals, and tools for
installing, using, and configuring them.

A flaw was found in the way certain HPLIP tools discovered devices using
the SNMP protocol. If a user ran certain HPLIP tools that search for
supported devices using SNMP, and a malicious user is able to send
specially-crafted SNMP responses, it could cause those HPLIP tools to crash
or, possibly, execute arbitrary code with the privileges of the user
running them. (CVE-2010-4267)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

Users of hplip should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-17" />
        <updated date="2011-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4267.html">CVE-2010-4267</cve>
                <bugzilla href="http://bugzilla.redhat.com/662740" id="662740">CVE-2010-4267 hplip: remote stack overflow vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154002" comment="hplip is earlier than 0:1.6.7-6.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154003" comment="hplip is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154006" comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154007" comment="libsane-hpaio is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154004" comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154005" comment="hpijs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154008" comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154009" comment="hplip3 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154010" comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154011" comment="hplip3-gui is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154016" comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154017" comment="hplip3-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154014" comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154015" comment="libsane-hpaio3 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154012" comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154013" comment="hplip3-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154018" comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154019" comment="hpijs3 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154024" comment="hplip is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154025" comment="hplip is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154028" comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154029" comment="hplip-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154026" comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154027" comment="libsane-hpaio is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154032" comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154033" comment="hplip-gui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154030" comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154031" comment="hplip-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110154034" comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110154035" comment="hpijs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110162" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0162: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0162-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0162.html" />
          <reference source="CVE" ref_id="CVE-2010-3859" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3859.html" />
          <reference source="CVE" ref_id="CVE-2010-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3876.html" />
          <reference source="CVE" ref_id="CVE-2010-4072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4072.html" />
          <reference source="CVE" ref_id="CVE-2010-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4073.html" />
          <reference source="CVE" ref_id="CVE-2010-4075" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4075.html" />
          <reference source="CVE" ref_id="CVE-2010-4080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4080.html" />
          <reference source="CVE" ref_id="CVE-2010-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4083.html" />
          <reference source="CVE" ref_id="CVE-2010-4157" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4157.html" />
          <reference source="CVE" ref_id="CVE-2010-4158" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4158.html" />
          <reference source="CVE" ref_id="CVE-2010-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4242.html" />
          <reference source="CVE" ref_id="CVE-2010-4249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4249.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A heap overflow flaw was found in the Linux kernel's Transparent
Inter-Process Communication protocol (TIPC) implementation. A local,
unprivileged user could use this flaw to escalate their privileges.
(CVE-2010-3859, Important)

* Missing sanity checks were found in gdth_ioctl_alloc() in the gdth driver
in the Linux kernel. A local user with access to "/dev/gdth" on a 64-bit
system could use these flaws to cause a denial of service or escalate their
privileges. (CVE-2010-4157, Moderate)

* A NULL pointer dereference flaw was found in the Bluetooth HCI UART
driver in the Linux kernel. A local, unprivileged user could use this flaw
to cause a denial of service. (CVE-2010-4242, Moderate)

* A flaw was found in the Linux kernel's garbage collector for AF_UNIX
sockets. A local, unprivileged user could use this flaw to trigger a
denial of service (out-of-memory condition). (CVE-2010-4249, Moderate)

* Missing initialization flaws were found in the Linux kernel. A local,
unprivileged user could use these flaws to cause information leaks.
(CVE-2010-3876, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080,
CVE-2010-4083, CVE-2010-4158, Low)

Red Hat would like to thank Alan Cox for reporting CVE-2010-4242; Vegard
Nossum for reporting CVE-2010-4249; Vasiliy Kulikov for reporting
CVE-2010-3876; Kees Cook for reporting CVE-2010-4072; and Dan Rosenberg for
reporting CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4083, and
CVE-2010-4158.

This update also fixes the following bugs:

* A flaw was found in the Linux kernel where, if used in conjunction with
another flaw that can result in a kernel Oops, could possibly lead to
privilege escalation. It does not affect Red Hat Enterprise Linux 4 as the
sysctl panic_on_oops variable is turned on by default. However, as a
preventive measure if the variable is turned off by an administrator, this
update addresses the issue. Red Hat would like to thank Nelson Elhage for
reporting this vulnerability. (BZ#659568)

* On Intel I/O Controller Hub 9 (ICH9) hardware, jumbo frame support is
achieved by using page-based sk_buff buffers without any packet split. The
entire frame data is copied to the page(s) rather than some to the
skb->data area and some to the page(s) when performing a typical
packet-split. This caused problems with the filtering code and frames were
getting dropped before they were received by listening applications. This
bug could eventually lead to the IP address being released and not being
able to be re-acquired from DHCP if the MTU (Maximum Transfer Unit) was
changed (for an affected interface using the e1000e driver). With this
update, frames are no longer dropped and an IP address is correctly
re-acquired after a previous release. (BZ#664667)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-18" />
        <updated date="2011-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3859.html">CVE-2010-3859</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3876.html">CVE-2010-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4072.html">CVE-2010-4072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4073.html">CVE-2010-4073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4075.html">CVE-2010-4075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4080.html">CVE-2010-4080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4083.html">CVE-2010-4083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4157.html">CVE-2010-4157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4158.html">CVE-2010-4158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4242.html">CVE-2010-4242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4249.html">CVE-2010-4249</cve>
                <bugzilla href="http://bugzilla.redhat.com/641410" id="641410">CVE-2010-4242 kernel: missing tty ops write function presence check in hci_uart_tty_open()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645867" id="645867">CVE-2010-3859 kernel: tipc: heap overflow in tipc_msg_build()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648656" id="648656">CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648658" id="648658">CVE-2010-4073 kernel: ipc/compat*.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648660" id="648660">CVE-2010-4075 kernel: drivers/serial/serial_core.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648669" id="648669">CVE-2010-4080 kernel: drivers/sound/pci/rme9652/hdsp.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648673" id="648673">CVE-2010-4083 kernel: ipc/sem.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649715" id="649715">CVE-2010-3876 kernel: net/packet/af_packet.c: reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651147" id="651147">CVE-2010-4157 kernel: gdth: integer overflow in ioc_general()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651698" id="651698">CVE-2010-4158 kernel: socket filters infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656756" id="656756">CVE-2010-4249 kernel: unix socket local dos</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659568" id="659568">CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162002" comment="kernel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162022" comment="kernel-doc is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162004" comment="kernel-devel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162014" comment="kernel-smp-devel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162015" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162018" comment="kernel-hugemem is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162017" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162012" comment="kernel-largesmp is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162013" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162008" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162009" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162006" comment="kernel-xenU is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162007" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110162010" comment="kernel-smp is earlier than 0:2.6.9-89.35.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110163" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0163: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0163-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0163.html" />
          <reference source="CVE" ref_id="CVE-2010-4526" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4526.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A flaw was found in the sctp_icmp_proto_unreachable() function in the
Linux kernel's Stream Control Transmission Protocol (SCTP) implementation.
A remote attacker could use this flaw to cause a denial of service.
(CVE-2010-4526, Important)

This update also fixes the following bugs:

* Due to an off-by-one error, gfs2_grow failed to take the very last "rgrp"
parameter into account when adding up the new free space. With this update,
the GFS2 kernel properly counts all the new resource groups and fixes the
"statfs" file correctly. (BZ#666792)

* Prior to this update, a multi-threaded application, which invoked
popen(3) internally, could cause a thread stall by FILE lock corruption.
The application program waited for a FILE lock in glibc, but the lock
seemed to be corrupted, which was caused by a race condition in the COW (Copy On Write) logic. With this update, the race condition was corrected and FILE lock corruption no longer occurs. (BZ#667050)

* If an error occurred during I/O, the SCSI driver reset the "megaraid_sas"
controller to restore it to normal state. However, on Red Hat Enterprise
Linux 5, the waiting time to allow a full reset completion for the
"megaraid_sas" controller was too short. The driver incorrectly recognized
the controller as stalled, and, as a result, the system stalled as well.
With this update, more time is given to the controller to properly restart,
thus, the controller operates as expected after being reset. (BZ#667141)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-18" />
        <updated date="2011-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4526.html">CVE-2010-4526</cve>
                <bugzilla href="http://bugzilla.redhat.com/664914" id="664914">CVE-2010-4526 kernel: sctp: a race between ICMP protocol unreachable and connect()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666792" id="666792">fsck.gfs2 reported statfs error after gfs2_grow [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667050" id="667050">COW corruption using popen(3). [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667141" id="667141">[RHEL5.6] megaraid_sas stalls after driver is reset [rhel-5.6.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163004" comment="kernel-headers is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163002" comment="kernel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163024" comment="kernel-doc is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163022" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163012" comment="kernel-devel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163008" comment="kernel-debug is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163018" comment="kernel-kdump is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163014" comment="kernel-xen-devel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163006" comment="kernel-debug-devel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163020" comment="kernel-PAE is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163016" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110163010" comment="kernel-xen is earlier than 0:2.6.18-238.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110164" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0164: mysql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0164.html" />
          <reference source="CVE" ref_id="CVE-2010-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3677.html" />
          <reference source="CVE" ref_id="CVE-2010-3678" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3678.html" />
          <reference source="CVE" ref_id="CVE-2010-3679" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3679.html" />
          <reference source="CVE" ref_id="CVE-2010-3680" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3680.html" />
          <reference source="CVE" ref_id="CVE-2010-3681" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3681.html" />
          <reference source="CVE" ref_id="CVE-2010-3682" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3682.html" />
          <reference source="CVE" ref_id="CVE-2010-3683" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3683.html" />
          <reference source="CVE" ref_id="CVE-2010-3833" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3833.html" />
          <reference source="CVE" ref_id="CVE-2010-3835" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3835.html" />
          <reference source="CVE" ref_id="CVE-2010-3836" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3836.html" />
          <reference source="CVE" ref_id="CVE-2010-3837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3837.html" />
          <reference source="CVE" ref_id="CVE-2010-3838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3838.html" />
          <reference source="CVE" ref_id="CVE-2010-3839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3839.html" />
          <reference source="CVE" ref_id="CVE-2010-3840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3840.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

The MySQL PolyFromWKB() function did not sanity check Well-Known Binary
(WKB) data, which could allow a remote, authenticated attacker to crash
mysqld. (CVE-2010-3840)

A flaw in the way MySQL processed certain JOIN queries could allow a
remote, authenticated attacker to cause excessive CPU use (up to 100%), if
a stored procedure contained JOIN queries, and that procedure was executed
twice in sequence. (CVE-2010-3839)

A flaw in the way MySQL processed queries that provide a mixture of numeric
and longblob data types to the LEAST or GREATEST function, could allow a
remote, authenticated attacker to crash mysqld. (CVE-2010-3838)

A flaw in the way MySQL processed PREPARE statements containing both
GROUP_CONCAT and the WITH ROLLUP modifier could allow a remote,
authenticated attacker to crash mysqld. (CVE-2010-3837)

MySQL did not properly pre-evaluate LIKE arguments in view prepare mode,
possibly allowing a remote, authenticated attacker to crash mysqld.
(CVE-2010-3836)

A flaw in the way MySQL processed statements that assign a value to a
user-defined variable and that also contain a logical value evaluation
could allow a remote, authenticated attacker to crash mysqld.
(CVE-2010-3835)

A flaw in the way MySQL evaluated the arguments of extreme-value functions,
such as LEAST and GREATEST, could allow a remote, authenticated attacker to
crash mysqld. (CVE-2010-3833)

A flaw in the way MySQL handled LOAD DATA INFILE requests allowed MySQL to
send OK packets even when there were errors. (CVE-2010-3683)

A flaw in the way MySQL processed EXPLAIN statements for some complex
SELECT queries could allow a remote, authenticated attacker to crash
mysqld. (CVE-2010-3682)

A flaw in the way MySQL processed certain alternating READ requests
provided by HANDLER statements could allow a remote, authenticated attacker
to crash mysqld. (CVE-2010-3681)

A flaw in the way MySQL processed CREATE TEMPORARY TABLE statements that
define NULL columns when using the InnoDB storage engine, could allow a
remote, authenticated attacker to crash mysqld. (CVE-2010-3680)

A flaw in the way MySQL processed certain values provided to the BINLOG
statement caused MySQL to read unassigned memory. A remote, authenticated
attacker could possibly use this flaw to crash mysqld. (CVE-2010-3679)

A flaw in the way MySQL processed SQL queries containing IN or CASE
statements, when a NULL argument was provided as one of the arguments to
the query, could allow a remote, authenticated attacker to crash mysqld.
(CVE-2010-3678)

A flaw in the way MySQL processed JOIN queries that attempt to retrieve
data from a unique SET column could allow a remote, authenticated attacker
to crash mysqld. (CVE-2010-3677)

Note: CVE-2010-3840, CVE-2010-3838, CVE-2010-3837, CVE-2010-3835,
CVE-2010-3833, CVE-2010-3682, CVE-2010-3681, CVE-2010-3680, CVE-2010-3678,
and CVE-2010-3677 only cause a temporary denial of service, as mysqld was
automatically restarted after each crash.

These updated packages upgrade MySQL to version 5.1.52. Refer to the MySQL
release notes for a full list of changes:

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-52.html

All MySQL users should upgrade to these updated packages, which correct
these issues. After installing this update, the MySQL server daemon
(mysqld) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-18" />
        <updated date="2011-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3677.html">CVE-2010-3677</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3678.html">CVE-2010-3678</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3679.html">CVE-2010-3679</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3680.html">CVE-2010-3680</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3681.html">CVE-2010-3681</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3682.html">CVE-2010-3682</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3683.html">CVE-2010-3683</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3833.html">CVE-2010-3833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3835.html">CVE-2010-3835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3836.html">CVE-2010-3836</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3837.html">CVE-2010-3837</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3838.html">CVE-2010-3838</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3839.html">CVE-2010-3839</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3840.html">CVE-2010-3840</cve>
                <bugzilla href="http://bugzilla.redhat.com/628040" id="628040">CVE-2010-3677 MySQL: Mysqld DoS (crash) by processing joins involving a table with a unique SET column (MySQL BZ#54575)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628062" id="628062">CVE-2010-3679 MySQL: Use of unassigned memory (valgrind errors / crash) by providing certain values to BINLOG statement (MySQL BZ#54393)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628172" id="628172">CVE-2010-3678  MySQL: mysqld DoS (crash) by processing IN / CASE statements with NULL arguments (MySQL bug #54477)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628192" id="628192">CVE-2010-3680 MySQL: mysqld DoS (assertion failure) by using temporary InnoDB engine tables with nullable columns (MySQL bug #54044)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628328" id="628328">CVE-2010-3682 MySQL: mysqld DoS (crash) by processing EXPLAIN statements for complex SQL queries (MySQL bug #52711)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628680" id="628680">CVE-2010-3681 MySQL: mysqld DoS (assertion failure) by alternate reads from two indexes on a table using the HANDLER interface (MySQL bug #54007)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628698" id="628698">CVE-2010-3683 MySQL: mysqld DoS (assertion failure) while reading the file back into a table (MySQL bug #52512)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640751" id="640751">CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640819" id="640819">CVE-2010-3835 MySQL: crash with user variables, assignments, joins... (MySQL Bug #55564)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640845" id="640845">CVE-2010-3836 MySQL: pre-evaluating LIKE arguments in view prepare mode causes crash (MySQL Bug#54568)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640856" id="640856">CVE-2010-3837 MySQL: crash when group_concat and "with rollup" in prepared statements (MySQL Bug#54476)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640858" id="640858">CVE-2010-3838 MySQL: crash with LONGBLOB and union or update with subquery (MySQL Bug#54461)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640861" id="640861">CVE-2010-3839 MySQL: server hangs during JOIN query in stored procedures called twice in a row (MySQL Bug#53544)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640865" id="640865">CVE-2010-3840 MySQL: crash when loading data into geometry function PolyFromWKB() (MySQL Bug#51875)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164017" comment="mysql-test is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164018" comment="mysql-test is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164005" comment="mysql is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164006" comment="mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164013" comment="mysql-libs is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164014" comment="mysql-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164011" comment="mysql-server is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164012" comment="mysql-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164009" comment="mysql-embedded is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164010" comment="mysql-embedded is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164019" comment="mysql-embedded-devel is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164020" comment="mysql-embedded-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164007" comment="mysql-bench is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164008" comment="mysql-bench is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110164015" comment="mysql-devel is earlier than 0:5.1.52-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110164016" comment="mysql-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110169" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0169-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0169.html" />
          <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html" />
          <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html" />
          <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes multiple vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2010-3553, CVE-2010-3557,
CVE-2010-3571)

This update also fixes the following bug:

* An error in the java-1.5.0-ibm RPM spec file caused an incorrect path to
be included in HtmlConverter, preventing it from running. (BZ#659710)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR12-FP3 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-20" />
        <updated date="2011-01-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3553.html">CVE-2010-3553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3557.html">CVE-2010-3557</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3571.html">CVE-2010-3571</cve>
                <bugzilla href="http://bugzilla.redhat.com/639904" id="639904">CVE-2010-3557 OpenJDK Swing mutable static (6938813)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642167" id="642167">CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642585" id="642585">CVE-2010-3571 JDK unspecified vulnerability in 2D component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659710" id="659710">IBM Java5 files modified &amp; Missing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169008" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169009" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169004" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169005" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169006" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169007" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169012" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169016" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169017" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169014" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169010" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169011" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169034" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169035" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169022" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169023" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169030" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169031" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169026" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169027" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169028" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169029" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169032" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169033" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110169024" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169025" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110170" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0170: libuser security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0170-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0170.html" />
          <reference source="CVE" ref_id="CVE-2011-0002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0002.html" />
    
    <description>The libuser library implements a standardized interface for manipulating
and administering user and group accounts. Sample applications that are
modeled after applications from the shadow password suite (shadow-utils)
are included in these packages.

It was discovered that libuser did not set the password entry correctly
when creating LDAP (Lightweight Directory Access Protocol) users. If an
administrator did not assign a password to an LDAP based user account,
either at account creation with luseradd, or with lpasswd after account
creation, an attacker could use this flaw to log into that account with a
default password string that should have been rejected. (CVE-2011-0002)

Note: LDAP administrators that have used libuser tools to add users should
check existing user accounts for plain text passwords, and reset them as
necessary.

Users of libuser should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-20" />
        <updated date="2011-01-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0002.html">CVE-2011-0002</cve>
                <bugzilla href="http://bugzilla.redhat.com/643227" id="643227">CVE-2011-0002 libuser creates LDAP users with a default password</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170004" comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170005" comment="libuser-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170002" comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170003" comment="libuser is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170012" comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170013" comment="libuser-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170014" comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170015" comment="libuser-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170010" comment="libuser is earlier than 0:0.56.13-4.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170011" comment="libuser is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170019" comment="libuser-devel is earlier than 0:0.52.5-1.1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170020" comment="libuser-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110170017" comment="libuser is earlier than 0:0.52.5-1.1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110170018" comment="libuser is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110176" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0176: java-1.6.0-openjdk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0176.html" />
          <reference source="CVE" ref_id="CVE-2010-3860" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3860.html" />
          <reference source="CVE" ref_id="CVE-2010-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4351.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The javaws command can be used to
launch Java Web Start applications.

A public static field declaration allowed untrusted JNLP (Java Network
Launching Protocol) applications to read privileged data. A remote attacker
could directly or indirectly read the values of restricted system
properties, such as "user.name", "user.home", and "java.home", which
untrusted applications should not be allowed to read. (CVE-2010-3860)

It was found that JNLPSecurityManager could silently return without
throwing an exception when permission was denied. If the javaws command was
used to launch a Java Web Start application that relies on this exception
being thrown, it could result in that application being run with elevated
privileges, allowing it to bypass security manager restrictions and gain
access to privileged functionality. (CVE-2010-4351)

Note: The RHSA-2010:0339 java-1.6.0-openjdk update installed javaws by
mistake. As part of the fixes for CVE-2010-3860 and CVE-2010-4351, this
update removes javaws.

Red Hat would like to thank the TippingPoint Zero Day Initiative project
for reporting CVE-2010-4351. The original issue reporter wishes to stay
anonymous.

This erratum also upgrades the OpenJDK package to IcedTea6 1.7.7. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-25" />
        <updated date="2011-01-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3860.html">CVE-2010-3860</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4351.html">CVE-2010-4351</cve>
                <bugzilla href="http://bugzilla.redhat.com/645843" id="645843">CVE-2010-3860 IcedTea System property information leak via public static</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663680" id="663680">CVE-2010-4351 IcedTea jnlp security manager bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110176002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.17.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110176004" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.17.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176005" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110176010" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.17.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110176006" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.17.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176007" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110176008" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.17.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110177" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0177: webkitgtk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0177.html" />
          <reference source="CVE" ref_id="CVE-2010-1780" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1780.html" />
          <reference source="CVE" ref_id="CVE-2010-1782" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1782.html" />
          <reference source="CVE" ref_id="CVE-2010-1783" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1783.html" />
          <reference source="CVE" ref_id="CVE-2010-1784" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1784.html" />
          <reference source="CVE" ref_id="CVE-2010-1785" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1785.html" />
          <reference source="CVE" ref_id="CVE-2010-1786" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1786.html" />
          <reference source="CVE" ref_id="CVE-2010-1787" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1787.html" />
          <reference source="CVE" ref_id="CVE-2010-1788" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1788.html" />
          <reference source="CVE" ref_id="CVE-2010-1790" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1790.html" />
          <reference source="CVE" ref_id="CVE-2010-1792" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1792.html" />
          <reference source="CVE" ref_id="CVE-2010-1793" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1793.html" />
          <reference source="CVE" ref_id="CVE-2010-1807" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1807.html" />
          <reference source="CVE" ref_id="CVE-2010-1812" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1812.html" />
          <reference source="CVE" ref_id="CVE-2010-1814" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1814.html" />
          <reference source="CVE" ref_id="CVE-2010-1815" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1815.html" />
          <reference source="CVE" ref_id="CVE-2010-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3113.html" />
          <reference source="CVE" ref_id="CVE-2010-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3114.html" />
          <reference source="CVE" ref_id="CVE-2010-3115" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3115.html" />
          <reference source="CVE" ref_id="CVE-2010-3116" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3116.html" />
          <reference source="CVE" ref_id="CVE-2010-3119" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3119.html" />
          <reference source="CVE" ref_id="CVE-2010-3255" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3255.html" />
          <reference source="CVE" ref_id="CVE-2010-3257" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3257.html" />
          <reference source="CVE" ref_id="CVE-2010-3259" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3259.html" />
          <reference source="CVE" ref_id="CVE-2010-3812" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3812.html" />
          <reference source="CVE" ref_id="CVE-2010-3813" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3813.html" />
          <reference source="CVE" ref_id="CVE-2010-4197" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4197.html" />
          <reference source="CVE" ref_id="CVE-2010-4198" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4198.html" />
          <reference source="CVE" ref_id="CVE-2010-4204" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4204.html" />
          <reference source="CVE" ref_id="CVE-2010-4206" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4206.html" />
          <reference source="CVE" ref_id="CVE-2010-4577" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4577.html" />
    
    <description>WebKitGTK+ is the port of the portable web rendering engine WebKit to the
GTK+ platform.

Multiple memory corruption flaws were found in WebKit. Malicious web
content could cause an application using WebKitGTK+ to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2010-1782, CVE-2010-1783, CVE-2010-1784,
CVE-2010-1785, CVE-2010-1787, CVE-2010-1788, CVE-2010-1790, CVE-2010-1792,
CVE-2010-1807, CVE-2010-1814, CVE-2010-3114, CVE-2010-3116, CVE-2010-3119,
CVE-2010-3255, CVE-2010-3812, CVE-2010-4198)

Multiple use-after-free flaws were found in WebKit. Malicious web content
could cause an application using WebKitGTK+ to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2010-1780, CVE-2010-1786, CVE-2010-1793, CVE-2010-1812,
CVE-2010-1815, CVE-2010-3113, CVE-2010-3257, CVE-2010-4197, CVE-2010-4204)

Two array index errors, leading to out-of-bounds memory reads, were found
in WebKit. Malicious web content could cause an application using
WebKitGTK+ to crash. (CVE-2010-4206, CVE-2010-4577)

A flaw in WebKit could allow malicious web content to trick a user into
thinking they are visiting the site reported by the location bar, when the
page is actually content controlled by an attacker. (CVE-2010-3115)

It was found that WebKit did not correctly restrict read access to images
created from the "canvas" element. Malicious web content could allow a
remote attacker to bypass the same-origin policy and potentially access
sensitive image data. (CVE-2010-3259)

A flaw was found in the way WebKit handled DNS prefetching. Even when it
was disabled, web content containing certain "link" elements could cause
WebKitGTK+ to perform DNS prefetching. (CVE-2010-3813)

Users of WebKitGTK+ should upgrade to these updated packages, which contain
WebKitGTK+ version 1.2.6, and resolve these issues. All running
applications that use WebKitGTK+ must be restarted for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-25" />
        <updated date="2011-01-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1780.html">CVE-2010-1780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1782.html">CVE-2010-1782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1783.html">CVE-2010-1783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1784.html">CVE-2010-1784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1785.html">CVE-2010-1785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1786.html">CVE-2010-1786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1787.html">CVE-2010-1787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1788.html">CVE-2010-1788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1790.html">CVE-2010-1790</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1792.html">CVE-2010-1792</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1793.html">CVE-2010-1793</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1807.html">CVE-2010-1807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1812.html">CVE-2010-1812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1814.html">CVE-2010-1814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1815.html">CVE-2010-1815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3113.html">CVE-2010-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3114.html">CVE-2010-3114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3115.html">CVE-2010-3115</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3116.html">CVE-2010-3116</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3119.html">CVE-2010-3119</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3255.html">CVE-2010-3255</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3257.html">CVE-2010-3257</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3259.html">CVE-2010-3259</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3812.html">CVE-2010-3812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3813.html">CVE-2010-3813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4197.html">CVE-2010-4197</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4198.html">CVE-2010-4198</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4204.html">CVE-2010-4204</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4206.html">CVE-2010-4206</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4577.html">CVE-2010-4577</cve>
                <bugzilla href="http://bugzilla.redhat.com/627366" id="627366">CVE-2010-1780 CVE-2010-1782 CVE-2010-1783 CVE-2010-1784 CVE-2010-1785 CVE-2010-1786 CVE-2010-1787 CVE-2010-1788 CVE-2010-1790 CVE-2010-1792 CVE-2010-1793 WebKit: multiple vulnerabilities in WebKitGTK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627703" id="627703">CVE-2010-1807 webkit: input validation error when parsing certain NaN values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628032" id="628032">CVE-2010-3113 webkit: memory corruption when handling SVG documents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628035" id="628035">CVE-2010-3114 webkit: bad cast with text editing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628071" id="628071">CVE-2010-3115 webkit: address bar spoofing with history bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628076" id="628076">CVE-2010-3119 webkit: DoS due to improper Ruby support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631939" id="631939">CVE-2010-1812 webkit: use-after-free flaw in handling of selections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631946" id="631946">CVE-2010-1814 webkit: memory corruption flaw when handling form menus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631948" id="631948">CVE-2010-1815 webkit: use-after-free flaw when handling scrollbars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640353" id="640353">CVE-2010-3116 webkit: memory corruption with MIME types</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640357" id="640357">CVE-2010-3257 webkit: stale pointer issue with focusing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640360" id="640360">CVE-2010-3259 webkit: cross-origin image theft</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645914" id="645914">CVE-2010-3255 webkit: DoS via improper handling of counter nodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656115" id="656115">CVE-2010-4197 WebKit: Use-after-free vulnerabiity related to text editing causes memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656118" id="656118">CVE-2010-4198 WebKit: Memory corruption due to improper handling of large text area</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656126" id="656126">CVE-2010-4204 WebKit: Use-after-free vulnerability related frame object</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656129" id="656129">CVE-2010-4206 WebKit: Array index error during processing of an SVG document</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667022" id="667022">CVE-2010-3812 webkit: Integer overflow in WebKit's handling of Text objects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667024" id="667024">CVE-2010-3813 webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667025" id="667025">CVE-2010-4577 webkit: CSS Font Face Parsing Type Confusion Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110177007" comment="webkitgtk-devel is earlier than 0:1.2.6-2.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110177008" comment="webkitgtk-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110177009" comment="webkitgtk-doc is earlier than 0:1.2.6-2.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110177010" comment="webkitgtk-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110177005" comment="webkitgtk is earlier than 0:1.2.6-2.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110177006" comment="webkitgtk is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110180" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0180: pango security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0180.html" />
          <reference source="CVE" ref_id="CVE-2011-0020" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0020.html" />
    
    <description>Pango is a library used for the layout and rendering of internationalized
text.

An input sanitization flaw, leading to a heap-based buffer overflow, was
found in the way Pango displayed font files when using the FreeType font
engine back end. If a user loaded a malformed font file with an application
that uses Pango, it could cause the application to crash or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0020)

Users of pango and evolution28-pango are advised to upgrade to these
updated packages, which contain a backported patch to resolve this issue.
After installing the updated packages, you must restart your system or
restart your X session for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-27" />
        <updated date="2011-01-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0020.html">CVE-2011-0020</cve>
                <bugzilla href="http://bugzilla.redhat.com/671122" id="671122">CVE-2011-0020 pango: Heap-based buffer overflow by rendering glyph box for certain FT_Bitmap objects</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180004" comment="pango-devel is earlier than 0:1.14.9-8.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180005" comment="pango-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180002" comment="pango is earlier than 0:1.14.9-8.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180003" comment="pango is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180012" comment="pango-devel is earlier than 0:1.28.1-3.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180013" comment="pango-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180010" comment="pango is earlier than 0:1.28.1-3.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180011" comment="pango is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180017" comment="evolution28-pango-devel is earlier than 0:1.14.9-13.el4_10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180018" comment="evolution28-pango-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110180015" comment="evolution28-pango is earlier than 0:1.14.9-13.el4_10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180016" comment="evolution28-pango is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110181" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0181: openoffice.org and openoffice.org2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0181-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0181.html" />
          <reference source="CVE" ref_id="CVE-2010-3450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3450.html" />
          <reference source="CVE" ref_id="CVE-2010-3451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3451.html" />
          <reference source="CVE" ref_id="CVE-2010-3452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3452.html" />
          <reference source="CVE" ref_id="CVE-2010-3453" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3453.html" />
          <reference source="CVE" ref_id="CVE-2010-3454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3454.html" />
          <reference source="CVE" ref_id="CVE-2010-4643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4643.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled
the installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues.
Upstream acknowledges Dan Rosenberg of Virtual Security Research as the
original reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-28" />
        <updated date="2011-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3450.html">CVE-2010-3450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3451.html">CVE-2010-3451</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3452.html">CVE-2010-3452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3453.html">CVE-2010-3453</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3454.html">CVE-2010-3454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4643.html">CVE-2010-4643</cve>
                <bugzilla href="http://bugzilla.redhat.com/602324" id="602324">CVE-2010-3450 OpenOffice.org: directory traversal flaws in handling of XSLT jar filter descriptions and OXT extension files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640241" id="640241">CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640950" id="640950">CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640954" id="640954">CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641282" id="641282">CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667588" id="667588">CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181006" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.7.el4_8.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181002" comment="openoffice.org is earlier than 0:1.1.5-10.7.el4_8.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181008" comment="openoffice.org-kde is earlier than 0:1.1.5-10.7.el4_8.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181009" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181004" comment="openoffice.org-libs is earlier than 0:1.1.5-10.7.el4_8.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181126" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181127" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181106" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181107" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181082" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181083" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181068" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181069" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181066" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181067" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181052" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181053" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181038" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181039" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181026" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181027" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181088" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181089" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181076" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181077" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181070" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181071" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181024" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181025" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181020" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181021" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181086" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181087" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181048" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181049" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181018" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181019" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181098" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181099" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181080" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181081" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181034" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181035" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181022" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181023" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181010" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181011" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181120" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181121" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181112" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181113" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181110" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181111" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181104" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181105" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181100" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181101" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181094" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181095" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181092" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181093" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181072" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181073" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181062" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181063" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181054" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181055" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181050" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181051" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181040" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181041" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181122" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181123" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181046" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181047" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181036" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181037" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181028" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181029" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181016" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181017" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181096" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181097" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181084" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181085" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181078" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181079" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181064" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181065" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181058" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181059" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181042" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181043" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181030" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181031" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181014" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181015" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181124" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181125" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181116" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181117" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181060" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181061" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181012" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181013" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181118" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181119" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181114" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181115" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181108" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181109" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181090" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181091" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181074" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181075" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181056" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181057" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181044" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181045" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181032" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181033" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110181102" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110181103" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110182" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0182: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0182-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0182.html" />
          <reference source="CVE" ref_id="CVE-2010-3450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3450.html" />
          <reference source="CVE" ref_id="CVE-2010-3451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3451.html" />
          <reference source="CVE" ref_id="CVE-2010-3452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3452.html" />
          <reference source="CVE" ref_id="CVE-2010-3453" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3453.html" />
          <reference source="CVE" ref_id="CVE-2010-3454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3454.html" />
          <reference source="CVE" ref_id="CVE-2010-3689" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3689.html" />
          <reference source="CVE" ref_id="CVE-2010-4253" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4253.html" />
          <reference source="CVE" ref_id="CVE-2010-4643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4643.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain Microsoft Office PowerPoint files. An attacker could use
this flaw to create a specially-crafted Microsoft Office PowerPoint file
that, when opened, would cause OpenOffice.org to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org. (CVE-2010-4253)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled the
installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

A flaw was found in the script that launches OpenOffice.org. In some
situations, a "." character could be included in the LD_LIBRARY_PATH
variable, allowing a local attacker to execute arbitrary code with the
privileges of the user running OpenOffice.org, if that user ran
OpenOffice.org from within an attacker-controlled directory.
(CVE-2010-3689)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues; and
Dmitri Gribenko for reporting the CVE-2010-3689 issue. Upstream
acknowledges Dan Rosenberg of Virtual Security Research as the original
reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-28" />
        <updated date="2011-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3450.html">CVE-2010-3450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3451.html">CVE-2010-3451</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3452.html">CVE-2010-3452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3453.html">CVE-2010-3453</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3454.html">CVE-2010-3454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3689.html">CVE-2010-3689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4253.html">CVE-2010-4253</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4643.html">CVE-2010-4643</cve>
                <bugzilla href="http://bugzilla.redhat.com/602324" id="602324">CVE-2010-3450 OpenOffice.org: directory traversal flaws in handling of XSLT jar filter descriptions and OXT extension files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640241" id="640241">CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640950" id="640950">CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640954" id="640954">CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641224" id="641224">CVE-2010-3689 OpenOffice.org: soffice insecure LD_LIBRARY_PATH setting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641282" id="641282">CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658259" id="658259">CVE-2010-4253 OpenOffice.org:  heap based buffer overflow in PPT import</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667588" id="667588">CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182002" comment="openoffice.org is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182030" comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182031" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182102" comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182103" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182054" comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182055" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182078" comment="openoffice.org-ure is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182079" comment="openoffice.org-ure is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182156" comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182157" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182148" comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182149" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182024" comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182025" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182026" comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182027" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182068" comment="openoffice.org-calc is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182069" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182104" comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182105" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182032" comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182033" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182040" comment="openoffice.org-testtools is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182041" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182122" comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182123" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182012" comment="openoffice.org-headless is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182013" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182066" comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182067" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182134" comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182135" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182106" comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182107" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182016" comment="openoffice.org-base is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182017" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182098" comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182099" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182058" comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182059" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182132" comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182133" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182050" comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182051" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182130" comment="openoffice.org-draw is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182131" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182150" comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182151" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182076" comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182077" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182020" comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182021" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182094" comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182095" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182064" comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182065" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182048" comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182049" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182096" comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182097" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182108" comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182109" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182124" comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182125" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182006" comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182007" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182086" comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182087" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182042" comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182043" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182074" comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182075" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182110" comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182111" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182144" comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182145" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182082" comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182083" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182142" comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182143" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182018" comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182019" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182052" comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182053" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182004" comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182005" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182146" comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182147" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182046" comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182047" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182060" comment="openoffice.org-writer is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182061" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182140" comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182141" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182056" comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182057" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182034" comment="openoffice.org-sdk is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182035" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182118" comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182119" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182092" comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182093" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182038" comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182039" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182084" comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182085" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182070" comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182071" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182010" comment="openoffice.org-math is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182011" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182044" comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182045" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182154" comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182155" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182014" comment="openoffice.org-core is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182015" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182112" comment="openoffice.org-impress is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182113" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182128" comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182129" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182152" comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182153" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182100" comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182101" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182116" comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182117" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182114" comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182115" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182008" comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182009" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182090" comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182091" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182080" comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182081" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182136" comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182137" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182072" comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182073" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182022" comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182023" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182126" comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182127" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182088" comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182089" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182138" comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182139" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182036" comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182037" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182120" comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182121" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182028" comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182029" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110182062" comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.5.el5_5.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110182063" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110183" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0183: openoffice.org security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0183-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0183.html" />
          <reference source="CVE" ref_id="CVE-2010-3450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3450.html" />
          <reference source="CVE" ref_id="CVE-2010-3451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3451.html" />
          <reference source="CVE" ref_id="CVE-2010-3452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3452.html" />
          <reference source="CVE" ref_id="CVE-2010-3453" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3453.html" />
          <reference source="CVE" ref_id="CVE-2010-3454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3454.html" />
          <reference source="CVE" ref_id="CVE-2010-3689" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3689.html" />
          <reference source="CVE" ref_id="CVE-2010-4253" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4253.html" />
          <reference source="CVE" ref_id="CVE-2010-4643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4643.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain Microsoft Office PowerPoint files. An attacker could use
this flaw to create a specially-crafted Microsoft Office PowerPoint file
that, when opened, would cause OpenOffice.org to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org. (CVE-2010-4253)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled the
installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

A flaw was found in the script that launches OpenOffice.org. In some
situations, a "." character could be included in the LD_LIBRARY_PATH
variable, allowing a local attacker to execute arbitrary code with the
privileges of the user running OpenOffice.org, if that user ran
OpenOffice.org from within an attacker-controlled directory.
(CVE-2010-3689)

Red Hat would like to thank OpenOffice.org for reporting the CVE-2010-3451,
CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, and CVE-2010-4643 issues; and
Dmitri Gribenko for reporting the CVE-2010-3689 issue. Upstream
acknowledges Dan Rosenberg of Virtual Security Research as the original
reporter of the CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, and
CVE-2010-3454 issues.

This update also fixes the following bug:

* OpenOffice.org did not create a lock file when opening a file that was on
a share mounted via SFTP. Additionally, if there was a lock file, it was
ignored. This could result in data loss if a file in this situation was
opened simultaneously by another user. (BZ#671087)

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-01-28" />
        <updated date="2011-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3450.html">CVE-2010-3450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3451.html">CVE-2010-3451</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3452.html">CVE-2010-3452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3453.html">CVE-2010-3453</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3454.html">CVE-2010-3454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3689.html">CVE-2010-3689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4253.html">CVE-2010-4253</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4643.html">CVE-2010-4643</cve>
                <bugzilla href="http://bugzilla.redhat.com/602324" id="602324">CVE-2010-3450 OpenOffice.org: directory traversal flaws in handling of XSLT jar filter descriptions and OXT extension files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640241" id="640241">CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640950" id="640950">CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640954" id="640954">CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641224" id="641224">CVE-2010-3689 OpenOffice.org: soffice insecure LD_LIBRARY_PATH setting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641282" id="641282">CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658259" id="658259">CVE-2010-4253 OpenOffice.org:  heap based buffer overflow in PPT import</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667588" id="667588">CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671087" id="671087">[fix available] file locks are not created with gvfs-sftp volumes with OpenOffice.org</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183067" comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183068" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183015" comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183016" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183055" comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183056" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183007" comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183008" comment="openoffice.org-math-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183051" comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183052" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183269" comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183270" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183195" comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183196" comment="openoffice.org-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183057" comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183058" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183059" comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183060" comment="openoffice.org-langpack-en is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183017" comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183018" comment="openoffice.org-impress-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183125" comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183126" comment="openoffice.org-math is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183145" comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183146" comment="openoffice.org-langpack-dz is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183265" comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183266" comment="openoffice.org-draw is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183249" comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183250" comment="autocorr-fa is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183219" comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183220" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183039" comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183040" comment="openoffice.org-langpack-sr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183061" comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183062" comment="autocorr-en is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183251" comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183252" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183245" comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183246" comment="autocorr-pt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183031" comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183032" comment="openoffice.org-bsh is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183149" comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183150" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183041" comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183042" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183237" comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183238" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183025" comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183026" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183075" comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183076" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183151" comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183152" comment="openoffice.org-draw-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183035" comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183036" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183095" comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183096" comment="autocorr-nl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183255" comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183256" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183253" comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183254" comment="autocorr-lb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183203" comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183204" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183069" comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183070" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183019" comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183020" comment="autocorr-sv is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183087" comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183088" comment="autocorr-ko is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183267" comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183268" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183239" comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183240" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183063" comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183064" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183135" comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183136" comment="openoffice.org-presenter-screen is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183207" comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183208" comment="autocorr-es is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183189" comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183190" comment="openoffice.org-brand is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183157" comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183158" comment="openoffice.org-base-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183193" comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183194" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183223" comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183224" comment="openoffice.org-headless is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183091" comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183092" comment="autocorr-zh is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183083" comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183084" comment="autocorr-eu is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183175" comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183176" comment="autocorr-fi is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183049" comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183050" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183165" comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183166" comment="openoffice.org-calc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183005" comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183006" comment="openoffice.org is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183029" comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183030" comment="broffice.org-math is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183037" comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183038" comment="openoffice.org-pdfimport is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183141" comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183142" comment="openoffice.org-rhino is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183143" comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183144" comment="autocorr-hu is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183229" comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183230" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183211" comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183212" comment="broffice.org-draw is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183197" comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183198" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183085" comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183086" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183133" comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183134" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183011" comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183012" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183093" comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183094" comment="autocorr-da is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183047" comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183048" comment="broffice.org-calc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183137" comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183138" comment="openoffice.org-wiki-publisher is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183081" comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183082" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183097" comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183098" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183161" comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183162" comment="openoffice.org-presentation-minimizer is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183163" comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183164" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183071" comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183072" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183089" comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183090" comment="autocorr-ga is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183065" comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183066" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183231" comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183232" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183109" comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183110" comment="autocorr-af is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183169" comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183170" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183105" comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183106" comment="autocorr-tr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183127" comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183128" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183243" comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183244" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183225" comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183226" comment="autocorr-ja is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183103" comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183104" comment="autocorr-de is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183275" comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183276" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183241" comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183242" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183121" comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183122" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183021" comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183022" comment="broffice.org-writer is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183159" comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183160" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183167" comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183168" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183115" comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183116" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183221" comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183222" comment="autocorr-fr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183023" comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183024" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183185" comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183186" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183077" comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183078" comment="autocorr-cs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183155" comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183156" comment="openoffice.org-report-builder is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183215" comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183216" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183227" comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183228" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183171" comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183172" comment="openoffice.org-langpack-pa is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183173" comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183174" comment="openoffice.org-langpack-uk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183261" comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183262" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183209" comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183210" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183101" comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183102" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183273" comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183274" comment="openoffice.org-calc-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183119" comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183120" comment="autocorr-it is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183177" comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183178" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183199" comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183200" comment="openoffice.org-langpack-ro is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183045" comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183046" comment="broffice.org-impress is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183013" comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183014" comment="openoffice.org-langpack-mai_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183009" comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183010" comment="autocorr-lt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183113" comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183114" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183129" comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183130" comment="openoffice.org-testtools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183263" comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183264" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183233" comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183234" comment="openoffice.org-writer-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183271" comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183272" comment="openoffice.org-base is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183235" comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183236" comment="openoffice.org-ure is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183205" comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183206" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183179" comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183180" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183187" comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183188" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183153" comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183154" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183181" comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183182" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183107" comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183108" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183099" comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183100" comment="openoffice.org-writer is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183123" comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183124" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183247" comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183248" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183139" comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183140" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183213" comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183214" comment="autocorr-ru is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183079" comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183080" comment="broffice.org-brand is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183201" comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183202" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183147" comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183148" comment="autocorr-bg is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183053" comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183054" comment="openoffice.org-ogltrans is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183217" comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183218" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183111" comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183112" comment="autocorr-mn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183027" comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183028" comment="openoffice.org-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183131" comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183132" comment="autocorr-pl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183183" comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183184" comment="autocorr-vi is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183043" comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183044" comment="autocorr-sk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183259" comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183260" comment="openoffice.org-impress is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183257" comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183258" comment="openoffice.org-sdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183117" comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183118" comment="autocorr-sl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183073" comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183074" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183033" comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183034" comment="openoffice.org-opensymbol-fonts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110183191" comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110183192" comment="broffice.org-base is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110195" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0195: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0195-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5016.html" />
          <reference source="CVE" ref_id="CVE-2010-3709" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3709.html" />
          <reference source="CVE" ref_id="CVE-2010-3870" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3870.html" />
          <reference source="CVE" ref_id="CVE-2010-4645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4645.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way PHP converted certain floating point values
from string representation to a number. If a PHP script evaluated an
attacker's input in a numeric context, the PHP interpreter could cause high
CPU usage until the script execution time limit is reached. This issue only
affected i386 systems. (CVE-2010-4645)

A numeric truncation error and an input validation flaw were found in the
way the PHP utf8_decode() function decoded partial multi-byte sequences
for some multi-byte encodings, sending them to output without them being
escaped. An attacker could use these flaws to perform a cross-site
scripting attack. (CVE-2009-5016, CVE-2010-3870)

A NULL pointer dereference flaw was found in the PHP
ZipArchive::getArchiveComment function. If a script used this function to
inspect a specially-crafted ZIP archive file, it could cause the PHP
interpreter to crash. (CVE-2010-3709)

All php users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-03" />
        <updated date="2011-02-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-5016.html">CVE-2009-5016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3709.html">CVE-2010-3709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3870.html">CVE-2010-3870</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4645.html">CVE-2010-4645</cve>
                <bugzilla href="http://bugzilla.redhat.com/649056" id="649056">CVE-2010-3870 php: XSS mitigation bypass via utf8_decode()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651206" id="651206">CVE-2010-3709 php: NULL pointer dereference in ZipArchive::getArchiveComment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652836" id="652836">CVE-2009-5016 php: XSS and SQL injection bypass via crafted overlong UTF-8 encoded string</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667806" id="667806">CVE-2010-4645 php: hang on numeric value 2.2250738585072011e-308 with x87 fpu</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195055" comment="php-gd is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195056" comment="php-gd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195023" comment="php-soap is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195024" comment="php-soap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195019" comment="php-odbc is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195020" comment="php-odbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195009" comment="php-common is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195010" comment="php-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195027" comment="php-pspell is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195028" comment="php-pspell is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195007" comment="php-mysql is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195008" comment="php-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195005" comment="php is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195006" comment="php is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195051" comment="php-xmlrpc is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195052" comment="php-xmlrpc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195043" comment="php-cli is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195044" comment="php-cli is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195025" comment="php-enchant is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195026" comment="php-enchant is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195015" comment="php-process is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195016" comment="php-process is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195041" comment="php-mbstring is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195042" comment="php-mbstring is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195021" comment="php-xml is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195022" comment="php-xml is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195013" comment="php-pgsql is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195014" comment="php-pgsql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195053" comment="php-dba is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195054" comment="php-dba is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195031" comment="php-devel is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195032" comment="php-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195029" comment="php-intl is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195030" comment="php-intl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195047" comment="php-bcmath is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195048" comment="php-bcmath is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195039" comment="php-imap is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195040" comment="php-imap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195035" comment="php-snmp is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195036" comment="php-snmp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195033" comment="php-zts is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195034" comment="php-zts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195037" comment="php-embedded is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195038" comment="php-embedded is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195011" comment="php-tidy is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195012" comment="php-tidy is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195049" comment="php-recode is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195050" comment="php-recode is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195045" comment="php-ldap is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195046" comment="php-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110195017" comment="php-pdo is earlier than 0:5.3.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195018" comment="php-pdo is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110196" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0196: php53 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0196-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0196.html" />
          <reference source="CVE" ref_id="CVE-2010-3710" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3710.html" />
          <reference source="CVE" ref_id="CVE-2010-4156" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4156.html" />
          <reference source="CVE" ref_id="CVE-2010-4645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4645.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A flaw was found in the way PHP converted certain floating point values
from string representation to a number. If a PHP script evaluated an
attacker's input in a numeric context, the PHP interpreter could cause high
CPU usage until the script execution time limit is reached. This issue only
affected i386 systems. (CVE-2010-4645)

A stack memory exhaustion flaw was found in the way the PHP filter_var()
function validated email addresses. An attacker could use this flaw to
crash the PHP interpreter by providing excessively long input to be
validated as an email address. (CVE-2010-3710)

A memory disclosure flaw was found in the PHP multi-byte string extension.
If the mb_strcut() function was called with a length argument exceeding the
input string size, the function could disclose a portion of the PHP
interpreter's memory. (CVE-2010-4156)

All php53 users should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-03" />
        <updated date="2011-02-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3710.html">CVE-2010-3710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4156.html">CVE-2010-4156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4645.html">CVE-2010-4645</cve>
                <bugzilla href="http://bugzilla.redhat.com/646684" id="646684">CVE-2010-3710 php: DoS in filter_var() via long email string</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651682" id="651682">CVE-2010-4156 php information disclosure via mb_strcut()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667806" id="667806">CVE-2010-4645 php: hang on numeric value 2.2250738585072011e-308 with x87 fpu</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196028" comment="php53-mbstring is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196029" comment="php53-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196006" comment="php53-pgsql is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196007" comment="php53-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196042" comment="php53-intl is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196043" comment="php53-intl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196026" comment="php53-process is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196027" comment="php53-process is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196024" comment="php53-cli is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196025" comment="php53-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196004" comment="php53-imap is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196005" comment="php53-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196034" comment="php53-xml is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196035" comment="php53-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196014" comment="php53-bcmath is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196015" comment="php53-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196012" comment="php53-mysql is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196013" comment="php53-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196002" comment="php53 is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196003" comment="php53 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196018" comment="php53-dba is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196019" comment="php53-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196016" comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196017" comment="php53-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196040" comment="php53-soap is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196041" comment="php53-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196036" comment="php53-odbc is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196037" comment="php53-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196022" comment="php53-common is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196023" comment="php53-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196038" comment="php53-pspell is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196039" comment="php53-pspell is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196030" comment="php53-ldap is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196031" comment="php53-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196010" comment="php53-pdo is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196011" comment="php53-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196032" comment="php53-devel is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196033" comment="php53-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196020" comment="php53-gd is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196021" comment="php53-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110196008" comment="php53-snmp is earlier than 0:5.3.3-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196009" comment="php53-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110197" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0197: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0197.html" />
          <reference source="CVE" ref_id="CVE-2010-4015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4015.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

A stack-based buffer overflow flaw was found in the way PostgreSQL
processed certain tokens from an SQL query when the intarray module was
enabled on a particular database. An authenticated database user running a
specially-crafted SQL query could use this flaw to cause a temporary denial
of service (postgres daemon crash) or, potentially, execute arbitrary code
with the privileges of the database server. (CVE-2010-4015)

Red Hat would like to thank Geoff Keating of the Apple Product Security
team for reporting this issue.

For Red Hat Enterprise Linux 4, the updated postgresql packages contain a
backported patch for this issue; there are no other changes.

For Red Hat Enterprise Linux 5, the updated postgresql packages upgrade
PostgreSQL to version 8.1.23, and contain a backported patch for this
issue. Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.1/static/release.html

For Red Hat Enterprise Linux 6, the updated postgresql packages upgrade
PostgreSQL to version 8.4.7, which includes a fix for this issue. Refer to
the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-03" />
        <updated date="2011-02-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4015.html">CVE-2010-4015</cve>
                <bugzilla href="http://bugzilla.redhat.com/664402" id="664402">CVE-2010-4015 PostgreSQL: Stack-based buffer overflow by processing certain tokens from SQL query string when intarray module enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197004" comment="postgresql-docs is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197005" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197016" comment="postgresql-devel is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197017" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197008" comment="postgresql-test is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197009" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197006" comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197007" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197014" comment="postgresql-libs is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197015" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197018" comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197019" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197002" comment="postgresql is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197020" comment="postgresql-pl is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197021" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197012" comment="postgresql-server is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197013" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197010" comment="postgresql-python is earlier than 0:8.1.23-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197011" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197038" comment="postgresql-pltcl is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197039" comment="postgresql-pltcl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197036" comment="postgresql-docs is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197037" comment="postgresql-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197034" comment="postgresql-devel is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197035" comment="postgresql-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197044" comment="postgresql-contrib is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197045" comment="postgresql-contrib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197032" comment="postgresql-plperl is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197033" comment="postgresql-plperl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197030" comment="postgresql-test is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197031" comment="postgresql-test is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197028" comment="postgresql-plpython is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197029" comment="postgresql-plpython is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197040" comment="postgresql-libs is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197041" comment="postgresql-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197026" comment="postgresql is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197027" comment="postgresql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197042" comment="postgresql-server is earlier than 0:8.4.7-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197043" comment="postgresql-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197063" comment="postgresql-jdbc is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197064" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197059" comment="postgresql-docs is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197060" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197057" comment="postgresql-devel is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197058" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197053" comment="postgresql-test is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197054" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197051" comment="postgresql-contrib is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197052" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197061" comment="postgresql-libs is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197062" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197055" comment="postgresql-tcl is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197056" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197047" comment="postgresql is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197048" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197067" comment="postgresql-python is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197068" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197065" comment="postgresql-server is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197066" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110197049" comment="postgresql-pl is earlier than 0:7.4.30-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197050" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110198" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0198: postgresql84 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0198-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0198.html" />
          <reference source="CVE" ref_id="CVE-2010-4015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4015.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

A stack-based buffer overflow flaw was found in the way PostgreSQL
processed certain tokens from an SQL query when the intarray module was
enabled on a particular database. An authenticated database user running a
specially-crafted SQL query could use this flaw to cause a temporary denial
of service (postgres daemon crash) or, potentially, execute arbitrary code
with the privileges of the database server. (CVE-2010-4015)

Red Hat would like to thank Geoff Keating of the Apple Product Security
team for reporting this issue.

These updated postgresql84 packages upgrade PostgreSQL to version 8.4.7.
Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-03" />
        <updated date="2011-02-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4015.html">CVE-2010-4015</cve>
                <bugzilla href="http://bugzilla.redhat.com/664402" id="664402">CVE-2010-4015 PostgreSQL: Stack-based buffer overflow by processing certain tokens from SQL query string when intarray module enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198024" comment="postgresql84-tcl is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198025" comment="postgresql84-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198004" comment="postgresql84-docs is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198005" comment="postgresql84-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198014" comment="postgresql84-python is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198015" comment="postgresql84-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198010" comment="postgresql84-plpython is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198011" comment="postgresql84-plpython is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198018" comment="postgresql84-libs is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198019" comment="postgresql84-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198008" comment="postgresql84-test is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198009" comment="postgresql84-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198006" comment="postgresql84-server is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198007" comment="postgresql84-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198016" comment="postgresql84-plperl is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198017" comment="postgresql84-plperl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198012" comment="postgresql84-pltcl is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198013" comment="postgresql84-pltcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198022" comment="postgresql84-devel is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198023" comment="postgresql84-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198002" comment="postgresql84 is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198003" comment="postgresql84 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110198020" comment="postgresql84-contrib is earlier than 0:8.4.7-1.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198021" comment="postgresql84-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110199" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0199: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0199-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0199.html" />
          <reference source="CVE" ref_id="CVE-2011-0281" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0281.html" />
          <reference source="CVE" ref_id="CVE-2011-0282" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0282.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed principal names that were not null terminated, when the KDC was
configured to use an LDAP back end. A remote attacker could use this flaw
to crash the KDC via a specially-crafted request. (CVE-2011-0282)

A denial of service flaw was found in the way the MIT Kerberos KDC
processed certain principal names when the KDC was configured to use an
LDAP back end. A remote attacker could use this flaw to cause the KDC to
hang via a specially-crafted request. (CVE-2011-0281)

Red Hat would like to thank the MIT Kerberos Team for reporting these
issues. Upstream acknowledges Kevin Longfellow of Oracle Corporation as the
original reporter of the CVE-2011-0281 issue.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-08" />
        <updated date="2011-02-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0281.html">CVE-2011-0281</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0282.html">CVE-2011-0282</cve>
                <bugzilla href="http://bugzilla.redhat.com/668719" id="668719">CVE-2011-0281 krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668726" id="668726">CVE-2011-0282 krb5: KDC crash when using LDAP backend caused by a special principal name (MITKRB5-SA-2011-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199008" comment="krb5-libs is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199009" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199010" comment="krb5-devel is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199011" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199006" comment="krb5-server is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199007" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199012" comment="krb5-server-ldap is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199013" comment="krb5-server-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199002" comment="krb5 is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110199004" comment="krb5-workstation is earlier than 0:1.6.1-55.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110199005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110200" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0200: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0200-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0200.html" />
          <reference source="CVE" ref_id="CVE-2010-4022" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4022.html" />
          <reference source="CVE" ref_id="CVE-2011-0281" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0281.html" />
          <reference source="CVE" ref_id="CVE-2011-0282" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0282.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

A NULL pointer dereference flaw was found in the way the MIT Kerberos KDC
processed principal names that were not null terminated, when the KDC was
configured to use an LDAP back end. A remote attacker could use this flaw
to crash the KDC via a specially-crafted request. (CVE-2011-0282)

A denial of service flaw was found in the way the MIT Kerberos KDC
processed certain principal names when the KDC was configured to use an
LDAP back end. A remote attacker could use this flaw to cause the KDC to
hang via a specially-crafted request. (CVE-2011-0281)

A denial of service flaw was found in the way the MIT Kerberos V5 slave KDC
update server (kpropd) processed certain update requests for KDC database
propagation. A remote attacker could use this flaw to terminate the kpropd
daemon via a specially-crafted update request. (CVE-2010-4022)

Red Hat would like to thank the MIT Kerberos Team for reporting the
CVE-2011-0282 and CVE-2011-0281 issues. Upstream acknowledges Kevin
Longfellow of Oracle Corporation as the original reporter of the
CVE-2011-0281 issue.

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-08" />
        <updated date="2011-02-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4022.html">CVE-2010-4022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0281.html">CVE-2011-0281</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0282.html">CVE-2011-0282</cve>
                <bugzilla href="http://bugzilla.redhat.com/664009" id="664009">CVE-2010-4022 krb5: kpropd unexpected termination on invalid input (MITKRB5-SA-2011-001)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668719" id="668719">CVE-2011-0281 krb5: KDC hang when using LDAP backend caused by special principal name (MITKRB5-SA-2011-002)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668726" id="668726">CVE-2011-0282 krb5: KDC crash when using LDAP backend caused by a special principal name (MITKRB5-SA-2011-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200015" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200016" comment="krb5-pkinit-openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200007" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200008" comment="krb5-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200013" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200014" comment="krb5-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200017" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200018" comment="krb5-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200011" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200012" comment="krb5-server-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200005" comment="krb5 is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200006" comment="krb5 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110200009" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200010" comment="krb5-workstation is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110206" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0206: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0206.html" />
          <reference source="CVE" ref_id="CVE-2011-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0558.html" />
          <reference source="CVE" ref_id="CVE-2011-0559" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0559.html" />
          <reference source="CVE" ref_id="CVE-2011-0560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0560.html" />
          <reference source="CVE" ref_id="CVE-2011-0561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0561.html" />
          <reference source="CVE" ref_id="CVE-2011-0571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0571.html" />
          <reference source="CVE" ref_id="CVE-2011-0572" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0572.html" />
          <reference source="CVE" ref_id="CVE-2011-0573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0573.html" />
          <reference source="CVE" ref_id="CVE-2011-0574" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0574.html" />
          <reference source="CVE" ref_id="CVE-2011-0575" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0575.html" />
          <reference source="CVE" ref_id="CVE-2011-0577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0577.html" />
          <reference source="CVE" ref_id="CVE-2011-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0578.html" />
          <reference source="CVE" ref_id="CVE-2011-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0607.html" />
          <reference source="CVE" ref_id="CVE-2011-0608" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0608.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed on the Adobe security page APSB11-02, listed
in the References section.

Multiple security flaws were found in the way flash-plugin displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
potentially, execute arbitrary code when the victim loaded a page
containing the specially-crafted SWF content. (CVE-2011-0558,
CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572,
CVE-2011-0573, CVE-2011-0574, CVE-2011-0575, CVE-2011-0577, CVE-2011-0578,
CVE-2011-0607, CVE-2011-0608)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.2.152.27.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-09" />
        <updated date="2011-02-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0558.html">CVE-2011-0558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0559.html">CVE-2011-0559</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0560.html">CVE-2011-0560</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0561.html">CVE-2011-0561</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0571.html">CVE-2011-0571</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0572.html">CVE-2011-0572</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0573.html">CVE-2011-0573</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0574.html">CVE-2011-0574</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0575.html">CVE-2011-0575</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0577.html">CVE-2011-0577</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0578.html">CVE-2011-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0607.html">CVE-2011-0607</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0608.html">CVE-2011-0608</cve>
                <bugzilla href="http://bugzilla.redhat.com/676226" id="676226">CVE-2011-0558 CVE-2011-0559 CVE-2011-0560 CVE-2011-0561 CVE-2011-0571 CVE-2011-0572 CVE-2011-0573 CVE-2011-0574 CVE-2011-0575 CVE-2011-0577 CVE-2011-0578 CVE-2011-0607 CVE-2011-0608 flash-plugin: multiple code execution flaws (APSB11-02)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110206005" comment="flash-plugin is earlier than 0:10.2.152.27-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110214" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0214: java-1.6.0-openjdk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0214-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0214.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Java-based applications to hang, for instance if they parse Double values
in a specially-crafted HTTP request. (CVE-2010-4476)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve this issue. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-10" />
        <updated date="2011-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.18.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214008" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.18.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176005" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214010" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.18.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214006" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.18.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176007" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214004" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.18.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214016" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214017" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214018" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214019" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214022" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214023" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214020" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214021" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110214024" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214025" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110219" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0219: Red Hat Enterprise Linux 4 - 1-Year End Of Life Notice (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0219.html" />
    
    <description>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-28" />
        <updated date="2011-02-28" />
                <bugzilla href="http://bugzilla.redhat.com/669039" id="669039">Send Out RHEL 4 1-Year EOL Notice</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110219002" comment="redhat-release is earlier than 0:4Desktop-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110219004" comment="redhat-release is earlier than 0:4AS-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110219005" comment="redhat-release is earlier than 0:4ES-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110219006" comment="redhat-release is earlier than 0:4WS-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110256" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0256: dhcp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0256.html" />
          <reference source="CVE" ref_id="CVE-2011-0413" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0413.html" />
    
    <description>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. DHCPv6 is the DHCP protocol version for IPv6 networks.

A flaw was found in the way the dhcpd daemon processed certain DHCPv6
messages for addresses that had previously been declined and marked as
abandoned internally. If a remote attacker sent such messages to dhcpd, it
could cause dhcpd to crash due to an assertion failure if it was running as
a DHCPv6 server. (CVE-2011-0413)

Red Hat would like to thank Internet Systems Consortium for reporting this
issue.

Users running dhcpd as a DHCPv6 server should upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all DHCP servers will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-15" />
        <updated date="2011-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0413.html">CVE-2011-0413</cve>
                <bugzilla href="http://bugzilla.redhat.com/672755" id="672755">CVE-2011-0413 dhcp: unexpected abort caused by a DHCPv6 decline message</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110256009" comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256010" comment="dhclient is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110256007" comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256008" comment="dhcp-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110256005" comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256006" comment="dhcp is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110257" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0257: subversion security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0257-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0257.html" />
          <reference source="CVE" ref_id="CVE-2010-4539" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4539.html" />
          <reference source="CVE" ref_id="CVE-2010-4644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4644.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.

A server-side memory leak was found in the Subversion server. If a
malicious, remote user performed "svn blame" or "svn log" operations on
certain repository files, it could cause the Subversion server to consume
a large amount of system memory. (CVE-2010-4644)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
(for use with the Apache HTTP Server) processed certain requests. If a
malicious, remote user issued a certain type of request to display a
collection of Subversion repositories on a host that has the
SVNListParentPath directive enabled, it could cause the httpd process
serving the request to crash. Note that SVNListParentPath is not enabled by
default. (CVE-2010-4539)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-15" />
        <updated date="2011-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4539.html">CVE-2010-4539</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4644.html">CVE-2010-4644</cve>
                <bugzilla href="http://bugzilla.redhat.com/667407" id="667407">CVE-2010-4539 Subversion (mod_dav_svn): DoS (crash) by processing certain requests to display all available repositories to a web browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667763" id="667763">CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257006" comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257007" comment="subversion-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257002" comment="subversion is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257003" comment="subversion is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257012" comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257013" comment="subversion-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257008" comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257009" comment="subversion-ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257010" comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257011" comment="subversion-javahl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110257004" comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257005" comment="mod_dav_svn is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110258" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0258: subversion security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0258-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0258.html" />
          <reference source="CVE" ref_id="CVE-2010-3315" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3315.html" />
          <reference source="CVE" ref_id="CVE-2010-4539" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4539.html" />
          <reference source="CVE" ref_id="CVE-2010-4644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4644.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

An access restriction bypass flaw was found in the mod_dav_svn module. If
the SVNPathAuthz directive was set to "short_circuit", certain access rules
were not enforced, possibly allowing sensitive repository data to be leaked
to remote users. Note that SVNPathAuthz is set to "On" by default.
(CVE-2010-3315)

A server-side memory leak was found in the Subversion server. If a
malicious, remote user performed "svn blame" or "svn log" operations on
certain repository files, it could cause the Subversion server to consume
a large amount of system memory. (CVE-2010-4644)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests. If a malicious, remote user issued a certain
type of request to display a collection of Subversion repositories on a
host that has the SVNListParentPath directive enabled, it could cause the
httpd process serving the request to crash. Note that SVNListParentPath is
not enabled by default. (CVE-2010-4539)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-15" />
        <updated date="2011-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3315.html">CVE-2010-3315</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4539.html">CVE-2010-4539</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4644.html">CVE-2010-4644</cve>
                <bugzilla href="http://bugzilla.redhat.com/640317" id="640317">CVE-2010-3315 Subversion: Access restriction bypass by checkout of the root of the repository</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667407" id="667407">CVE-2010-4539 Subversion (mod_dav_svn): DoS (crash) by processing certain requests to display all available repositories to a web browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667763" id="667763">CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258019" comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258020" comment="subversion-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258009" comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258010" comment="subversion-kde is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258005" comment="subversion is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258006" comment="subversion is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258017" comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258018" comment="subversion-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258015" comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258016" comment="subversion-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258007" comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258008" comment="subversion-ruby is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258021" comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258022" comment="subversion-javahl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258013" comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258014" comment="mod_dav_svn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110258011" comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258012" comment="subversion-svn2cl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110260" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0260: python security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0260-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0260.html" />
          <reference source="CVE" ref_id="CVE-2009-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4134.html" />
          <reference source="CVE" ref_id="CVE-2010-1449" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1449.html" />
          <reference source="CVE" ref_id="CVE-2010-1450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1450.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

Multiple flaws were found in the Python rgbimg module. If an application
written in Python was using the rgbimg module and loaded a
specially-crafted SGI image file, it could cause the application to crash
or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2009-4134, CVE-2010-1449, CVE-2010-1450)

This update also fixes the following bugs:

* Python 2.3.4's time.strptime() function did not correctly handle the "%W"
week number format string. This update backports the _strptime
implementation from Python 2.3.6, fixing this issue. (BZ#436001)

* Python 2.3.4's socket.htons() function returned partially-uninitialized
data on IBM System z, generally leading to incorrect results. (BZ#513341)

* Python 2.3.4's pwd.getpwuid() and grp.getgrgid() functions did not
support the full range of user and group IDs on 64-bit architectures,
leading to "OverflowError" exceptions for large input values. This update
adds support for the full range of user and group IDs on 64-bit
architectures. (BZ#497540)

Users of Python should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-16" />
        <updated date="2011-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4134.html">CVE-2009-4134</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1449.html">CVE-2010-1449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1450.html">CVE-2010-1450</cve>
                <bugzilla href="http://bugzilla.redhat.com/497540" id="497540">grp module does not support whole uid/gid range</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/541698" id="541698">CVE-2009-4134 CVE-2010-1449 CVE-2010-1450 python: rgbimg: multiple security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110260010" comment="python-devel is earlier than 0:2.3.4-14.9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260011" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110260006" comment="python-docs is earlier than 0:2.3.4-14.9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260007" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110260004" comment="tkinter is earlier than 0:2.3.4-14.9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260005" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110260002" comment="python is earlier than 0:2.3.4-14.9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110260008" comment="python-tools is earlier than 0:2.3.4-14.9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260009" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110261" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0261: bash security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0261-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0261.html" />
          <reference source="CVE" ref_id="CVE-2008-5374" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5374.html" />
    
    <description>Bash (Bourne-again shell) is the default shell for Red Hat Enterprise
Linux.

It was found that certain scripts bundled with the Bash documentation
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files accessible to the victim running the
scripts. (CVE-2008-5374)

This update also fixes the following bugs:

* If a child process's PID was the same as the PID of a previously ended
child process, Bash did not wait for that child process. In some cases this
caused "Resource temporarily unavailable" errors. With this update, Bash
recycles PIDs and waits for processes with recycled PIDs. (BZ#521134)

* Bash's built-in "read" command had a memory leak when "read" failed due
to no input (pipe for stdin). With this update, the memory is correctly
freed. (BZ#537029)

* Bash did not correctly check for a valid multi-byte string when setting
the IFS value, causing Bash to crash. With this update, Bash checks the
multi-byte string and no longer crashes. (BZ#539536)

* Bash incorrectly set locale settings when using the built-in "export"
command and setting the locale on the same line (for example, with
"LC_ALL=C export LC_ALL"). With this update, Bash correctly sets locale
settings. (BZ#539538)

All bash users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-16" />
        <updated date="2011-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5374.html">CVE-2008-5374</cve>
                <bugzilla href="http://bugzilla.redhat.com/475474" id="475474">CVE-2008-5374 bash: Insecure temporary file use in aliasconv.sh, aliasconv.bash, cshtobash (symlink attack)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521134" id="521134">Bash doesn't wait for backgrounded process if its PID is recycled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110261002" comment="bash is earlier than 0:3.0-27.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110261003" comment="bash is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110262" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0262: sendmail security and bug fix update  (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0262-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0262.html" />
          <reference source="CVE" ref_id="CVE-2009-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4565.html" />
    
    <description>Sendmail is a Mail Transport Agent (MTA) used to send mail between
machines.

A flaw was found in the way sendmail handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick sendmail into accepting it by mistake, allowing the attacker to
perform a man-in-the-middle attack or bypass intended client certificate
authentication. (CVE-2009-4565) 

The CVE-2009-4565 issue only affected configurations using TLS with
certificate verification and CommonName checking enabled, which is not a
typical configuration.

This update also fixes the following bugs:

* Previously, sendmail did not correctly handle mail messages that had a
long first header line. A line with more than 2048 characters was split,
causing the part of the line exceeding the limit, as well as all of the
following mail headers, to be incorrectly handled as the message body.
(BZ#499450)

* When an SMTP-sender is sending mail data to sendmail, it may spool that
data to a file in the mail queue. It was found that, if the SMTP-sender
stopped sending data and a timeout occurred, the file may have been left
stalled in the mail queue, instead of being deleted. This update may not
correct this issue for every situation and configuration. Refer to the
Solution section for further information. (BZ#434645)

* Previously, the sendmail macro MAXHOSTNAMELEN used 64 characters as the
limit for the hostname length. However, in some cases, it was used against
an FQDN length, which has a maximum length of 255 characters. With this
update, the MAXHOSTNAMELEN limit has been changed to 255. (BZ#485380)

All sendmail users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
sendmail will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-16" />
        <updated date="2011-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4565.html">CVE-2009-4565</cve>
                <bugzilla href="http://bugzilla.redhat.com/434645" id="434645">DATA timeouts leave behind stale df files in mqueue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485380" id="485380">sendmail applies MAXHOSTNAMELEN for FQDN.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/552622" id="552622">CVE-2009-4565 sendmail: incorrect verification of SSL certificate with NUL in name</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110262002" comment="sendmail is earlier than 0:8.13.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110262003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110262006" comment="sendmail-doc is earlier than 0:8.13.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110262007" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110262004" comment="sendmail-devel is earlier than 0:8.13.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110262005" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110262008" comment="sendmail-cf is earlier than 0:8.13.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110262009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110263" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0263: Red Hat Enterprise Linux 4.9 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0263-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0263.html" />
          <reference source="CVE" ref_id="CVE-2010-4527" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4527.html" />
          <reference source="CVE" ref_id="CVE-2010-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4655.html" />
          <reference source="CVE" ref_id="CVE-2011-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0521.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the load_mixer_volumes() function in
the Linux kernel's Open Sound System (OSS) sound driver. On 64-bit PowerPC
systems, a local, unprivileged user could use this flaw to cause a denial
of service or escalate their privileges. (CVE-2010-4527, Important)

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-4527, and
Kees Cook for reporting CVE-2010-4655.

These updated kernel packages also fix hundreds of bugs and add numerous
enhancements. For details on individual bug fixes and enhancements included
in this update, refer to the Red Hat Enterprise Linux 4.9 Release Notes,
linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add these enhancements. The system must
be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-16" />
        <updated date="2011-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4527.html">CVE-2010-4527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4655.html">CVE-2010-4655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0521.html">CVE-2011-0521</cve>
                <bugzilla href="http://bugzilla.redhat.com/176848" id="176848">NLM: Fix Oops in nlmclnt_mark_reclaim()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189918" id="189918">kernel: serious ugliness in iget() uses by nfsd [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217829" id="217829">Powernow driver does not work properly with different voltage CPUs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247116" id="247116">RFE:  Add debug to bonding driver as module option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396631" id="396631">Increase timeout for device connection on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427998" id="427998">RHEL4: Can enter no tick idle mode with RCU pending leading to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445957" id="445957">Change "decode_getfattr: xdr error %d!" to dprintk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456047" id="456047">Kernel Panic at end_bio_bh_io_sync+44</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456649" id="456649">xenbus suspend_mutex remains locked after transaction failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457519" id="457519">groups_search() cannot handle large gid correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459466" id="459466">kernel: binfmt_misc.c: avoid potential kernel stack overflow [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459499" id="459499">proc_loginuid_write() uses simple_strtoul() on non-terminated array</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461038" id="461038">el4u5 pv guest user coredump crashing system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462717" id="462717">IPVS wrr scheduler bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472752" id="472752">BUG() in end_buffer_async_write()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476700" id="476700">Loss of USB HID devices when switching with a KVM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479090" id="479090">Panic in do_cciss_intr removeQ</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479264" id="479264">[RHEL4] lost siginfo when a signal queue is full</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480404" id="480404">kernel BUG at fs/mpage.c:417!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480937" id="480937">RHEL-4: Deadlock in Xen netfront driver.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481292" id="481292">[RHEL4.7] Original ether's status is keeping PROMISC MULTICAST mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481371" id="481371">PG_error bit is never cleared, even when a fresh I/O to the page succeeds</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483783" id="483783">kernel hid-input.c divide error crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484415" id="484415">CCISS device-mapper-multipath support: missing sysfs attributes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485904" id="485904">[RHEL4] Netfilter modules unloading hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488931" id="488931">ACLs on NFS mounted directories disappear</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490148" id="490148">Xen domU, RAID1, LVM, iscsi target export with blockio bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491284" id="491284">[x86_64]: copy_user_c can zero more data than needed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492868" id="492868">Xen guest kernel  advertises absolute mouse pointer feature which it is incapable of setting up correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493780" id="493780">EL4U7 kernel bug fix update (Oracle bug 7916406 - JVM process hang)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494404" id="494404">[RHEL4.5] Even if a process have received data but schedule() in select() cannot return</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494688" id="494688">e1000e: sporadic hang in netdump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495858" id="495858">show_partition() oops when race with rescan_partitions().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496201" id="496201">[RHEL4] Nscd consumes many cpu resources ( nearly 100% ) continuously.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496205" id="496205">PVFB frontend can send bogus screen updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496206" id="496206">xenkbd can crash when probe fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496209" id="496209">PVFB frontend mouse wheel support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498012" id="498012">Bonding driver updelay parameter actual behavior doesn't match documented behavior</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499355" id="499355">e1000_clean_tx_irq: Detected Tx Unit Hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499548" id="499548">kernel: proc: avoid information leaks to non-privileged processes [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499848" id="499848">[RHEL4-U8] Kernel - testing NMI watchdog ... CPU#0: NMI appears to be stuck (0)!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500637" id="500637">A bond's preferred primary setting is lost after bringing down and up of the primary slave.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500889" id="500889">Various IPv4/v6 SNMP counter fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500904" id="500904">renaming file on a share w/o write permissions causes oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501064" id="501064">[Stratus 4.9 bug] panic reading /proc/bus/input/devices during input device removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501335" id="501335">oops in nfs4_put_open_state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501500" id="501500">oops in nfsd_svc after forced unmount of stale nfs4 filesystem and reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501844" id="501844">kernel: random: ICE at get_random_int() [rhel-4.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502473" id="502473">Failure logging execve with lots of arguments</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502884" id="502884">NFSv4 Issue/slowdown when testing against the NetApp server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503489" id="503489">[NetApp 4.8 bug] Issues with "qioctlmod" module on RHEL4.8 hosts with QLogic FC inbox drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503762" id="503762">Adding bonding in balance-alb mode to bridge cause network connectivity to be lost [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504080" id="504080">MegaRAID SAS 1078 tape I/O errors when using mt erase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504156" id="504156">rtl8139 doesn't work with bonding in alb mode [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504279" id="504279">[RHEL 4] Lookups due to infinite loops in posix_locks_deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504593" id="504593">LRO patch to 4.7 breaks SANGOMA WANPIPE drivers build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504778" id="504778">FEAT RHEL4.9: Support new PCI IDS to support VX800 in via82cxxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504988" id="504988">[RHEL4 Xen]: i386 Guest crash when host has >= 64G RAM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505081" id="505081">[RHEL4.8 Xen]: Xenbus warnings in a FV guest on shutdown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505122" id="505122">Make Aborted Command (internal target failure) retryable at SCSI layer (sense B 44 00)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505506" id="505506">RHEL4.8: crash in do_cciss_request()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505591" id="505591">Bug in lockd prevents a locks being freed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506875" id="506875">kernel: ptrace: don't use REMOVE_LINKS/SET_LINKS for reparenting [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507527" id="507527">NFSD returns NFS4_OK when the owner opens a file with permission set to 000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507847" id="507847">Balloon driver gives up too easily when ballooning up under memory pressure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507951" id="507951">[4.8]Kernel can not increase the counter of Icmp6OutDestUnreachs when forwarding packet with address unreachable.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509220" id="509220">i386 rhel4.8 kvm guests crashes in virtio during installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509627" id="509627">kernel: fd leak if pipe() is called with an invalid address [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509816" id="509816">cciss: spinlock deadlock causes NMI on HP systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510184" id="510184">NFSD returns NFS4_OK(0) when OPEN with access==read/write on a read-denied/write-denied file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510395" id="510395">num_mtt settings of 2097152 fails in RHEL with infiniband HCA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510454" id="510454">[IPv6] No fragment header in ICMPv6 reply after packet_too_big message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511183" id="511183">kernel: build with -fno-delete-null-pointer-checks [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512641" id="512641">kernel: security: implement mmap_min_addr infrastructure [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514684" id="514684">NFS: mounted NFSv4/krb5 export inaccessible following an NFS server reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515274" id="515274">/proc/net/dev sometimes contains bogus values (BCM5706)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516076" id="516076">netconsole on e1000 cause "Badness in local_bh_enable at kernel/softirq.c:141"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516742" id="516742">CIFS - crash in small_smb_init</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517162" id="517162">cthon test5 failing on nfsv4 with rhel6 client vs. rhel4 server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517329" id="517329">[RHEL4.8] igb driver doesn't allocate enough buffer for ethtool_get_strings()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517523" id="517523">get_partstats() returns NULL and causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520018" id="520018">statfs on NFS partition always returns 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520299" id="520299">kernel: ipv4: make ip_append_data() handle NULL routing table [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522000" id="522000">[RFE ] Connlimit kernel module support [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523983" id="523983">kernel: ipt_recent: sanity check hit count [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524884" id="524884">reading from /proc/net/ip_conntrack returns ENOSPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525398" id="525398">RHEL4: Unable to write to file as non-root user with setuid and setgid bit set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525941" id="525941">OOM on i686 kernel-smp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527656" id="527656">bnx2x fails when iptables is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528066" id="528066">[Cisco/LSI 4.9 bug] mptctl module dereferences a userspace address, triggering a crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529063" id="529063">qla2xxx flash programming changes in 4.8 broke diskdump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/531914" id="531914">[4.6] TCP conntrack doesn't handle half-open state connection correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532045" id="532045">SCTP Messages out of order</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532593" id="532593">Upgrade from RHEL4U7 to U8 fails to bring up networking with forcedeth driver. [simple patch]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532858" id="532858">IBM HS22: SOL drops on bnx2 driver load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533299" id="533299">scsi device add/remove panic at sysfs_hash_and_remove</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537475" id="537475">Write barrier operations not working for libata and general SCSI disks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539506" id="539506">[4.7] wait4 blocks on non-existing pid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/541538" id="541538">[RHEL4 Xen]: PV guest crash on poweroff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/543823" id="543823">[RHEL4]: A new xenfb thread is created on every save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546251" id="546251">[RHEL4.5] select() cannot return in UDP/UNIX domain socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546324" id="546324">TCP receive window clamping problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/547213" id="547213">ext2online resize hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/548496" id="548496">[Emulex 4.9 bug] lpfc driver doesn't acquire lock when searching hba for target</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/552953" id="552953">"forcedeth" driver issue: eth0 fails to get ip address on boot with RHEL4 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/557122" id="557122">No output of xmit_hash_policy on IEEE 802.3ad Bonding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/557380" id="557380">Kernel panic due to recursive lock in 3c59x driver.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/558607" id="558607">e1000e: wol is broken in kernel 2.6.9-89.19</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/561108" id="561108">platform:ahern:rmmod hangs at 100% cpu removing usbnet module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/562949" id="562949">problems with aliased dentries and case-insensitivity in CIFS readdir code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/563920" id="563920">Please implement upstream fix for potential filesystem corruption bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/568271" id="568271">[QLogic 4.9 bug] qla2xxx: Fix srb cache destroy issue on driver unload and FDMI registration issue (8.02.10.01.04.09-d)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/569668" id="569668">[RHEL4] boot hangs if scsi read capacity fails on faulty non system drive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/577178" id="577178">megaraid_sas: fix physical disk handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/577378" id="577378">NFSv3 file attributes are not updated by READDIRPLUS reply</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/585430" id="585430">Add log message for unhandled sense error REPORTED_LUNS_DATA_CHANGED</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/589897" id="589897">Lost the network in a KVM VM on top of 4.9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/591938" id="591938">cifs: busy file renames across directories should fail with error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/594633" id="594633">kernel: security: testing the wrong variable in create_by_name() [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/604786" id="604786">second cifs mount to samba server fails when samba using security=ADS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/605455" id="605455">EXT3-fs error: do_get_write_access: OOM for frozen_buffer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607261" id="607261">Read from /proc/xen/xenbus does not honor O_NONBLOCK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607533" id="607533">Vhost:Fail to transfer file between two guests in same vlan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/610236" id="610236">[4u8] Bonding in ALB mode sends ARP in loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/614559" id="614559">sky2 issue with 4.8 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/620485" id="620485">system crashes due to corrupt net_device_wrapper structure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/621209" id="621209">[4u9] bonding: fix a race condition in calls to slave MII ioctls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623265" id="623265">bnx2: panic in bnx2_poll_work()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624117" id="624117">recording fails when usb audio device is connected to EHCI controller (ehci_hcd)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624713" id="624713">[RHEL4] Problems with aacraid - File system going into read-only.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629143" id="629143">Assertion failure in ext3_put_super() at fs/ext3/super.c:426: "list_empty(&amp;sbi->s_orphan)"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630564" id="630564">kernel: additional stack guard patches [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634632" id="634632">nfs4_reclaim_open_state: unhandled error -5. Zeroing state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637556" id="637556">Bonded interface doesn't issue IGMP report (join) on slave interface during failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637658" id="637658">[RHEL 4.8] 32-bit pvhvm guest on 64-bit host crash w/xm mem-set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640803" id="640803">[RHEL4.8.z] soft lockup on vlan with bonding in balance-alb mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641112" id="641112">bonding does not switch to slave</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643992" id="643992">Kernel maintainer's bz for spec file changes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645220" id="645220">[RFE] kernel: modules: sysctl to block module loading [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645633" id="645633">temporary loss of path to SAN results in persistent EIO with msync</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647187" id="647187">[netfront] ethtool -i should return proper information for netfront device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647196" id="647196">RFE: Virtio nic should support "ethtool -i virtio nic"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651334" id="651334">RHEL4.9: EHCI: AMD periodic frame list table quirk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653252" id="653252">kernel: restrict unprivileged access to kernel syslog [rhel-4.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653505" id="653505">[4.9 Regression] network is lost after balloon-up fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658824" id="658824">The USB storage cannot use >2TB.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662839" id="662839">[REG][4.9] Filesystem corruption happens on ext2 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667615" id="667615">CVE-2010-4527 kernel: buffer overflow in OSS load_mixer_volumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672398" id="672398">CVE-2011-0521 kernel: av7110 negative array offset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672428" id="672428">CVE-2010-4655 kernel: heap contents leak for CAP_NET_ADMIN via ethtool ioctl</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263002" comment="kernel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263022" comment="kernel-doc is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263004" comment="kernel-devel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263016" comment="kernel-smp-devel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162015" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263018" comment="kernel-hugemem is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263014" comment="kernel-largesmp-devel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162017" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263012" comment="kernel-largesmp is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162013" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263008" comment="kernel-xenU-devel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162009" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263006" comment="kernel-xenU is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162007" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110263010" comment="kernel-smp is earlier than 0:2.6.9-100.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110162011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110281" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0281: java-1.6.0-openjdk security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0281-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0281.html" />
          <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html" />
          <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html" />
          <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html" />
          <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html" />
          <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html" />
          <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A flaw was found in the Swing library. Forged TimerEvents could be used to
bypass SecurityManager checks, allowing access to otherwise blocked files
and directories. (CVE-2010-4465)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), which could lead to heap corruption. (CVE-2010-4469)

A flaw was found in the way JAXP (Java API for XML Processing) components
were handled, allowing them to be manipulated by untrusted applets. This
could be used to elevate privileges and bypass secure XML processing
restrictions. (CVE-2010-4470)

It was found that untrusted applets could create and place cache entries in
the name resolution cache. This could allow an attacker targeted
manipulation over name resolution until the OpenJDK VM is restarted.
(CVE-2010-4448)

It was found that the Java launcher provided by OpenJDK did not check the
LD_LIBRARY_PATH environment variable for insecure empty path elements. A
local attacker able to trick a user into running the Java launcher while
working from an attacker-writable directory could use this flaw to load an
untrusted library, subverting the Java security model. (CVE-2010-4450)

A flaw was found in the XML Digital Signature component in OpenJDK.
Untrusted code could use this flaw to replace the Java Runtime Environment
(JRE) XML Digital Signature Transform or C14N algorithm implementations to
intercept digital signature operations. (CVE-2010-4472)

Note: All of the above flaws can only be remotely triggered in OpenJDK by
calling the "appletviewer" application.

This update also provides one defense in depth patch. (BZ#676019)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-17" />
        <updated date="2011-02-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4448.html">CVE-2010-4448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4450.html">CVE-2010-4450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4465.html">CVE-2010-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4469.html">CVE-2010-4469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4470.html">CVE-2010-4470</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4472.html">CVE-2010-4472</cve>
                <bugzilla href="http://bugzilla.redhat.com/675942" id="675942">CVE-2010-4472 OpenJDK untrusted code allowed to replace DSIG/C14N implementation (6994263)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675958" id="675958">CVE-2010-4469 OpenJDK Hotspot verifier heap corruption (6878713)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675984" id="675984">CVE-2010-4465 OpenJDK Swing timer-based security manager bypass  (6907662)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676005" id="676005">CVE-2010-4470 OpenJDK JAXP untrusted component state manipulation (6927050)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676019" id="676019">CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676023" id="676023">CVE-2010-4448 OpenJDK DNS cache poisoning by untrusted applets (6981922)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676026" id="676026">CVE-2010-4450 OpenJDK Launcher incorrect processing of empty library path entries  (6983554)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.20.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281008" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.20.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176005" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281004" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.20.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281006" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.20.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176007" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281010" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.20.b17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281016" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214017" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281024" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214019" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281018" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214023" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281020" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214021" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110281022" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.b17.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214025" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110282" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0282: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0282.html" />
          <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html" />
          <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html" />
          <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html" />
          <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html" />
          <reference source="CVE" ref_id="CVE-2010-4451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4451.html" />
          <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html" />
          <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html" />
          <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html" />
          <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html" />
          <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html" />
          <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html" />
          <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html" />
          <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html" />
          <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html" />
          <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html" />
          <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html" />
          <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html" />
          <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html" />
          <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. Further
information about these flaws can be found on the "Oracle Java SE and Java
for Business Critical Patch Update Advisory" page, listed in the References
section. (CVE-2010-4422, CVE-2010-4447, CVE-2010-4448, CVE-2010-4450,
CVE-2010-4451, CVE-2010-4452, CVE-2010-4454, CVE-2010-4462, CVE-2010-4463,
CVE-2010-4465, CVE-2010-4466, CVE-2010-4467, CVE-2010-4468, CVE-2010-4469,
CVE-2010-4470, CVE-2010-4471, CVE-2010-4472, CVE-2010-4473, CVE-2010-4475,
CVE-2010-4476)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which resolve these issues. All running instances of Sun Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-17" />
        <updated date="2011-02-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4422.html">CVE-2010-4422</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4447.html">CVE-2010-4447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4448.html">CVE-2010-4448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4450.html">CVE-2010-4450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4451.html">CVE-2010-4451</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4452.html">CVE-2010-4452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4454.html">CVE-2010-4454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4462.html">CVE-2010-4462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4463.html">CVE-2010-4463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4465.html">CVE-2010-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4466.html">CVE-2010-4466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4467.html">CVE-2010-4467</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4468.html">CVE-2010-4468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4469.html">CVE-2010-4469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4470.html">CVE-2010-4470</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4471.html">CVE-2010-4471</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4472.html">CVE-2010-4472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4473.html">CVE-2010-4473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4475.html">CVE-2010-4475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675942" id="675942">CVE-2010-4472 OpenJDK untrusted code allowed to replace DSIG/C14N implementation (6994263)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675958" id="675958">CVE-2010-4469 OpenJDK Hotspot verifier heap corruption (6878713)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675984" id="675984">CVE-2010-4465 OpenJDK Swing timer-based security manager bypass  (6907662)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676005" id="676005">CVE-2010-4470 OpenJDK JAXP untrusted component state manipulation (6927050)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676019" id="676019">CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676023" id="676023">CVE-2010-4448 OpenJDK DNS cache poisoning by untrusted applets (6981922)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676026" id="676026">CVE-2010-4450 OpenJDK Launcher incorrect processing of empty library path entries  (6983554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677957" id="677957">CVE-2010-4475 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677958" id="677958">CVE-2010-4473 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677959" id="677959">CVE-2010-4468 JDK unspecified vulnerability in JDBC component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677960" id="677960">CVE-2010-4467 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677961" id="677961">CVE-2010-4466 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677963" id="677963">CVE-2010-4463 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677966" id="677966">CVE-2010-4462 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677967" id="677967">CVE-2010-4454 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677968" id="677968">CVE-2010-4452 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677969" id="677969">CVE-2010-4451 JDK unspecified vulnerability in Install component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677970" id="677970">CVE-2010-4447 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677971" id="677971">CVE-2010-4422 JDK unspecified vulnerability in Deployment component</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282008" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282009" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282002" comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282012" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282013" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282010" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282011" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282006" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282007" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282004" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282005" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282024" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282025" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282018" comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282019" comment="java-1.6.0-sun is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282028" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282029" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282026" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282027" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282022" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282023" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110282020" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282021" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110283" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0283: kernel security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0283-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0283.html" />
          <reference source="CVE" ref_id="CVE-2010-4165" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4165.html" />
          <reference source="CVE" ref_id="CVE-2010-4169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4169.html" />
          <reference source="CVE" ref_id="CVE-2010-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4243.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A divide-by-zero flaw was found in the tcp_select_initial_window()
function in the Linux kernel's TCP/IP protocol suite implementation. A
local, unprivileged user could use this flaw to trigger a denial of service
by calling setsockopt() with certain options. (CVE-2010-4165, Moderate)

* A use-after-free flaw in the mprotect() system call in the Linux kernel
could allow a local, unprivileged user to cause a local denial of service.
(CVE-2010-4169, Moderate)

* A flaw was found in the Linux kernel execve() system call implementation.
A local, unprivileged user could cause large amounts of memory to be
allocated but not visible to the OOM (Out of Memory) killer, triggering a
denial of service. (CVE-2010-4243, Moderate)

Red Hat would like to thank Steve Chen for reporting CVE-2010-4165, and
Brad Spengler for reporting CVE-2010-4243.

This update also fixes several bugs and adds two enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document linked to in the References
section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancements
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-22" />
        <updated date="2011-02-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4165.html">CVE-2010-4165</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4169.html">CVE-2010-4169</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4243.html">CVE-2010-4243</cve>
                <bugzilla href="http://bugzilla.redhat.com/625688" id="625688">CVE-2010-4243 kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651671" id="651671">CVE-2010-4169 kernel: perf bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652508" id="652508">CVE-2010-4165 kernel: possible kernel oops from user MSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652720" id="652720">read from virtio-serial returns if the host side is not connect to pipe [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658854" id="658854">[NetApp 6.1 bug] RHEL6.0 FC host hits kernel panic at scsi_error_handler [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658891" id="658891">[6.0.z FEAT] Port KVM bug fixes for cr_access to RHEL 6 [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659610" id="659610">[NetApp 6.1 bug] SCSI ALUA handler fails to handle ALUA transitioning properly [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660590" id="660590">[NetApp 6.1 bug] regression: allow offlined devs to be set to running [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661730" id="661730">NFS4 clients cannot reclaim locks after server reboot [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661731" id="661731">kernel: Problem with execve(2) reintroduced [rhel-6.1] [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661737" id="661737">xen PV guest kernel 2.6.32 processes lock up in D state [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662721" id="662721">Fix hot-unplug handling of virtio-console ports [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662921" id="662921">UV: WAR for interrupt-IOPort deadlock [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664398" id="664398">QLogic qla2xxx: Backport critical parts of 8.03.05.01.06.1-k0 to [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671342" id="671342">System panic in pskb_expand_head When arp_validate option is specified in bonding ARP monitor mode [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673978" id="673978">[NetApp 6.0 Bug] Erroneous TPG ID check in SCSI ALUA Handler [rhel-6.0.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283023" comment="kernel-firmware is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283009" comment="kernel-headers is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283005" comment="kernel is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283025" comment="kernel-doc is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283015" comment="kernel-devel is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283021" comment="perf is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283013" comment="kernel-debug is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283017" comment="kernel-kdump is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283011" comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283019" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110283007" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110290" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0290: java-1.6.0-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0290-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0290.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Java based applications to hang, for example, if they parsed Double values
in a specially-crafted HTTP request. (CVE-2010-4476)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR9 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-22" />
        <updated date="2011-02-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290012" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290013" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290008" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290004" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290005" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290014" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290015" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290010" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290011" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290016" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290017" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290006" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290007" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290028" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290029" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290022" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290023" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290032" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290033" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290034" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290035" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290026" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290027" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290030" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290031" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110290024" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290025" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110291" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0291: java-1.5.0-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0291-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0291.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Java based applications to hang, for example, if they parsed Double values
in a specially-crafted HTTP request. (CVE-2010-4476)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR12-FP3 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-22" />
        <updated date="2011-02-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291012" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169009" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291014" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169005" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291010" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169007" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291004" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291008" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169017" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291016" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291006" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169011" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291028" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169035" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291022" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169023" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291026" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169031" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291030" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169027" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291024" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169029" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291034" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169033" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110291032" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169025" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110292" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0292: java-1.4.2-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0292-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0292.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>The IBM 1.4.2 SR13-FP8 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Java based applications to hang, for example, if they parsed Double values
in a specially-crafted HTTP request. (CVE-2010-4476)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP8 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-22" />
        <updated date="2011-02-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292004" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292008" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292012" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110292006" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.8-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110301" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0301: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0301-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0301.html" />
          <reference source="CVE" ref_id="CVE-2011-0562" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0562.html" />
          <reference source="CVE" ref_id="CVE-2011-0563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0563.html" />
          <reference source="CVE" ref_id="CVE-2011-0565" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0565.html" />
          <reference source="CVE" ref_id="CVE-2011-0566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0566.html" />
          <reference source="CVE" ref_id="CVE-2011-0567" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0567.html" />
          <reference source="CVE" ref_id="CVE-2011-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0585.html" />
          <reference source="CVE" ref_id="CVE-2011-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0586.html" />
          <reference source="CVE" ref_id="CVE-2011-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0587.html" />
          <reference source="CVE" ref_id="CVE-2011-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0589.html" />
          <reference source="CVE" ref_id="CVE-2011-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0590.html" />
          <reference source="CVE" ref_id="CVE-2011-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0591.html" />
          <reference source="CVE" ref_id="CVE-2011-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0592.html" />
          <reference source="CVE" ref_id="CVE-2011-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0593.html" />
          <reference source="CVE" ref_id="CVE-2011-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0594.html" />
          <reference source="CVE" ref_id="CVE-2011-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0595.html" />
          <reference source="CVE" ref_id="CVE-2011-0596" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0596.html" />
          <reference source="CVE" ref_id="CVE-2011-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0598.html" />
          <reference source="CVE" ref_id="CVE-2011-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0599.html" />
          <reference source="CVE" ref_id="CVE-2011-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0600.html" />
          <reference source="CVE" ref_id="CVE-2011-0602" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0602.html" />
          <reference source="CVE" ref_id="CVE-2011-0603" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0603.html" />
          <reference source="CVE" ref_id="CVE-2011-0604" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0604.html" />
          <reference source="CVE" ref_id="CVE-2011-0606" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0606.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

This update fixes multiple vulnerabilities in Adobe Reader. These
vulnerabilities are detailed on the Adobe security page APSB11-03, listed
in the References section.

A specially-crafted PDF file could cause Adobe Reader to crash or,
potentially, execute arbitrary code as the user running Adobe Reader when
opened. (CVE-2011-0562, CVE-2011-0563, CVE-2011-0565, CVE-2011-0566,
CVE-2011-0567, CVE-2011-0585, CVE-2011-0586, CVE-2011-0589, CVE-2011-0590,
CVE-2011-0591, CVE-2011-0592, CVE-2011-0593, CVE-2011-0594, CVE-2011-0595,
CVE-2011-0596, CVE-2011-0598, CVE-2011-0599, CVE-2011-0600, CVE-2011-0602,
CVE-2011-0603, CVE-2011-0606)

Multiple security flaws were found in Adobe reader. A specially-crafted PDF
file could cause cross-site scripting (XSS) attacks against the user
running Adobe Reader when opened. (CVE-2011-0587, CVE-2011-0604)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 9.4.2, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-02-23" />
        <updated date="2011-02-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0562.html">CVE-2011-0562</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0563.html">CVE-2011-0563</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0565.html">CVE-2011-0565</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0566.html">CVE-2011-0566</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0567.html">CVE-2011-0567</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0585.html">CVE-2011-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0586.html">CVE-2011-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0587.html">CVE-2011-0587</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0589.html">CVE-2011-0589</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0590.html">CVE-2011-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0591.html">CVE-2011-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0592.html">CVE-2011-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0593.html">CVE-2011-0593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0594.html">CVE-2011-0594</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0595.html">CVE-2011-0595</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0596.html">CVE-2011-0596</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0598.html">CVE-2011-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0599.html">CVE-2011-0599</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0600.html">CVE-2011-0600</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0602.html">CVE-2011-0602</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0603.html">CVE-2011-0603</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0604.html">CVE-2011-0604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0606.html">CVE-2011-0606</cve>
                <bugzilla href="http://bugzilla.redhat.com/676157" id="676157">CVE-2011-0562 CVE-2011-0563 CVE-2011-0565 CVE-2011-0566 CVE-2011-0567 CVE-2011-0585 CVE-2011-0586 CVE-2011-0589 CVE-2011-0590 CVE-2011-0591 CVE-2011-0592 CVE-2011-0593 CVE-2011-0594 CVE-2011-0595 acroread: critical APSB11-03</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676158" id="676158">CVE-2011-0587 CVE-2011-0604 acroread: multiple XSS flaws (APSB11-03)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110301004" comment="acroread-plugin is earlier than 0:9.4.2-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110301002" comment="acroread is earlier than 0:9.4.2-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110301012" comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301013" comment="acroread-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110301010" comment="acroread is earlier than 0:9.4.2-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301011" comment="acroread is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110303" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0303: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0303-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0303.html" />
          <reference source="CVE" ref_id="CVE-2010-4249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4249.html" />
          <reference source="CVE" ref_id="CVE-2010-4251" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4251.html" />
          <reference source="CVE" ref_id="CVE-2010-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4655.html" />
          <reference source="CVE" ref_id="CVE-2010-4805" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4805.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the Linux kernel's garbage collector for AF_UNIX
sockets. A local, unprivileged user could use this flaw to trigger a
denial of service (out-of-memory condition). (CVE-2010-4249, Moderate)

* A flaw was found in the Linux kernel's networking subsystem. If the
number of packets received exceeded the receiver's buffer limit, they were
queued in a backlog, consuming memory, instead of being discarded. A remote
attacker could abuse this flaw to cause a denial of service (out-of-memory
condition). (CVE-2010-4251, Moderate)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

Red Hat would like to thank Vegard Nossum for reporting CVE-2010-4249, and
Kees Cook for reporting CVE-2010-4655.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4249.html">CVE-2010-4249</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4251.html">CVE-2010-4251</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4655.html">CVE-2010-4655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4805.html">CVE-2010-4805</cve>
                <bugzilla href="http://bugzilla.redhat.com/656756" id="656756">CVE-2010-4249 kernel: unix socket local dos</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657303" id="657303">CVE-2010-4251 CVE-2010-4805 kernel: unlimited socket backlog DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668976" id="668976">a test unit ready causes a panic on 5.6 (CCISS driver) [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669300" id="669300">Fix shrinking windows with window scaling [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670797" id="670797">panic in kfree() due to race condition in acpi_bus_receive_event() [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670807" id="670807">e1000 driver tracebacks when running under VMware ESX4 [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672428" id="672428">CVE-2010-4655 kernel: heap contents leak for CAP_NET_ADMIN via ethtool ioctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673983" id="673983">virtio_console driver never returns from selecting for write when the queue is full [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674273" id="674273">Flapping errors (and panic) with bonding and arp_interval while using be2net included in 2.6.18-238 [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678613" id="678613">vdso gettimeofday causes a segmentation fault [rhel-5.6.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303004" comment="kernel-headers is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303002" comment="kernel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303024" comment="kernel-doc is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303022" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303008" comment="kernel-devel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303010" comment="kernel-debug is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303016" comment="kernel-kdump is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303014" comment="kernel-xen-devel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303012" comment="kernel-debug-devel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303020" comment="kernel-PAE is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303018" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110303006" comment="kernel-xen is earlier than 0:2.6.18-238.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110305" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0305: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0305-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0305.html" />
          <reference source="CVE" ref_id="CVE-2011-0719" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0719.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A flaw was found in the way Samba handled file descriptors. If an attacker
were able to open a large number of file descriptors on the Samba server,
they could flip certain stack bits to "1" values, resulting in the Samba
server (smbd) crashing. (CVE-2011-0719)

Red Hat would like to thank the Samba team for reporting this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0719.html">CVE-2011-0719</cve>
                <bugzilla href="http://bugzilla.redhat.com/678328" id="678328">CVE-2011-0719 Samba unsafe fd_set usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305006" comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305007" comment="libsmbclient is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305008" comment="samba-client is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305004" comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305005" comment="libsmbclient-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305010" comment="samba-common is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305011" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305002" comment="samba is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305012" comment="samba-swat is earlier than 0:3.0.33-3.29.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305013" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305020" comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305021" comment="samba-domainjoin-gui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305032" comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305033" comment="samba-winbind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305028" comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305029" comment="libsmbclient is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305036" comment="samba-client is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305037" comment="samba-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305034" comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305035" comment="libsmbclient-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305024" comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305025" comment="samba-winbind-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305022" comment="samba-common is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305023" comment="samba-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305018" comment="samba is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305019" comment="samba is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305030" comment="samba-doc is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305031" comment="samba-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305026" comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305027" comment="samba-winbind-clients is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305038" comment="samba-swat is earlier than 0:3.5.4-68.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305039" comment="samba-swat is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305047" comment="samba-client is earlier than 0:3.0.33-0.30.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305048" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305043" comment="samba-common is earlier than 0:3.0.33-0.30.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305044" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305041" comment="samba is earlier than 0:3.0.33-0.30.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305042" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110305045" comment="samba-swat is earlier than 0:3.0.33-0.30.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305046" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110306" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0306: samba3x security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0306-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0306.html" />
          <reference source="CVE" ref_id="CVE-2011-0719" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0719.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A flaw was found in the way Samba handled file descriptors. If an attacker
were able to open a large number of file descriptors on the Samba server,
they could flip certain stack bits to "1" values, resulting in the Samba
server (smbd) crashing. (CVE-2011-0719)

Red Hat would like to thank the Samba team for reporting this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0719.html">CVE-2011-0719</cve>
                <bugzilla href="http://bugzilla.redhat.com/678328" id="678328">CVE-2011-0719 Samba unsafe fd_set usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306010" comment="samba3x-swat is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306011" comment="samba3x-swat is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306014" comment="samba3x-doc is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306015" comment="samba3x-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306006" comment="samba3x-client is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306007" comment="samba3x-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306008" comment="samba3x-winbind is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306009" comment="samba3x-winbind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306002" comment="samba3x is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306003" comment="samba3x is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306016" comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306017" comment="samba3x-winbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306012" comment="samba3x-common is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306013" comment="samba3x-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110306004" comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.70.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306005" comment="samba3x-domainjoin-gui is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110307" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0307: mailman security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0307.html" />
          <reference source="CVE" ref_id="CVE-2008-0564" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0564.html" />
          <reference source="CVE" ref_id="CVE-2010-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3089.html" />
          <reference source="CVE" ref_id="CVE-2011-0707" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0707.html" />
    
    <description>Mailman is a program used to help manage email discussion lists.

Multiple input sanitization flaws were found in the way Mailman displayed
usernames of subscribed users on certain pages. If a user who is subscribed
to a mailing list were able to trick a victim into visiting one of those
pages, they could perform a cross-site scripting (XSS) attack against the
victim. (CVE-2011-0707)

Multiple input sanitization flaws were found in the way Mailman displayed
mailing list information. A mailing list administrator could use this flaw
to conduct a cross-site scripting (XSS) attack against victims viewing a
list's "listinfo" page. (CVE-2008-0564, CVE-2010-3089)

Red Hat would like to thank Mark Sapiro for reporting the CVE-2011-0707 and
CVE-2010-3089 issues.

Users of mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0564.html">CVE-2008-0564</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3089.html">CVE-2010-3089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0707.html">CVE-2011-0707</cve>
                <bugzilla href="http://bugzilla.redhat.com/431526" id="431526">CVE-2008-0564 mailman: XSS triggerable by list administrator</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631881" id="631881">CVE-2010-3089 mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677375" id="677375">CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110307002" comment="mailman is earlier than 3:2.1.9-6.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110307003" comment="mailman is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110307005" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110307006" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110308" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0308: mailman security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0308.html" />
          <reference source="CVE" ref_id="CVE-2010-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3089.html" />
          <reference source="CVE" ref_id="CVE-2011-0707" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0707.html" />
    
    <description>Mailman is a program used to help manage email discussion lists.

Multiple input sanitization flaws were found in the way Mailman displayed
usernames of subscribed users on certain pages. If a user who is subscribed
to a mailing list were able to trick a victim into visiting one of those
pages, they could perform a cross-site scripting (XSS) attack against the
victim. (CVE-2011-0707)

Multiple input sanitization flaws were found in the way Mailman displayed
mailing list information. A mailing list administrator could use this flaw
to conduct a cross-site scripting (XSS) attack against victims viewing a
list's "listinfo" page. (CVE-2010-3089)

Red Hat would like to thank Mark Sapiro for reporting these issues.

Users of mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3089.html">CVE-2010-3089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0707.html">CVE-2011-0707</cve>
                <bugzilla href="http://bugzilla.redhat.com/631881" id="631881">CVE-2010-3089 mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677375" id="677375">CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110308005" comment="mailman is earlier than 3:2.1.12-14.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110308006" comment="mailman is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110309" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0309: pango security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0309-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0309.html" />
          <reference source="CVE" ref_id="CVE-2011-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0064.html" />
    
    <description>Pango is a library used for the layout and rendering of internationalized
text.

It was discovered that Pango did not check for memory reallocation failures
in the hb_buffer_ensure() function. An attacker able to trigger a
reallocation failure by passing sufficiently large input to an application
using Pango could use this flaw to crash the application or, possibly,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0064)

Red Hat would like to thank the Mozilla Security Team for reporting this
issue.

All pango users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing this update, you
must restart your system or restart the X server for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0064.html">CVE-2011-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/678563" id="678563">CVE-2011-0064 pango: missing memory reallocation failure checking in hb_buffer_ensure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110309007" comment="pango-devel is earlier than 0:1.28.1-3.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180013" comment="pango-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110309005" comment="pango is earlier than 0:1.28.1-3.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180011" comment="pango is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110310" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0310: firefox security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0310-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0310.html" />
          <reference source="CVE" ref_id="CVE-2010-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1585.html" />
          <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html" />
          <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html" />
          <reference source="CVE" ref_id="CVE-2011-0054" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0054.html" />
          <reference source="CVE" ref_id="CVE-2011-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0055.html" />
          <reference source="CVE" ref_id="CVE-2011-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0056.html" />
          <reference source="CVE" ref_id="CVE-2011-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0057.html" />
          <reference source="CVE" ref_id="CVE-2011-0058" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0058.html" />
          <reference source="CVE" ref_id="CVE-2011-0059" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0059.html" />
          <reference source="CVE" ref_id="CVE-2011-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0061.html" />
          <reference source="CVE" ref_id="CVE-2011-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0062.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox sanitized HTML content in extensions.
If an extension loaded or rendered malicious content using the
ParanoidFragmentSink class, it could fail to safely display the content,
causing Firefox to execute arbitrary JavaScript with the privileges of the
user running Firefox. (CVE-2010-1585)

A flaw was found in the way Firefox handled dialog boxes. An attacker could
use this flaw to create a malicious web page that would present a blank
dialog box that has non-functioning buttons. If a user closes the dialog
box window, it could unexpectedly grant the malicious web page elevated
privileges. (CVE-2011-0051)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-0053, CVE-2011-0055, CVE-2011-0058, CVE-2011-0062)

Several flaws were found in the way Firefox handled malformed JavaScript. A
website containing malicious JavaScript could cause Firefox to execute that
JavaScript with the privileges of the user running Firefox. (CVE-2011-0054,
CVE-2011-0056, CVE-2011-0057)

A flaw was found in the way Firefox handled malformed JPEG images. A
website containing a malicious JPEG image could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-0061)

A flaw was found in the way Firefox handled plug-ins that perform HTTP
requests. If a plug-in performed an HTTP request, and the server sent a 307
redirect response, the plug-in was not notified, and the HTTP request was
forwarded. The forwarded request could contain custom headers, which could
result in a Cross Site Request Forgery attack. (CVE-2011-0059)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.14. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bug:

* On Red Hat Enterprise Linux 4 and 5, running the "firefox
-setDefaultBrowser" command caused warnings such as the following:

libgnomevfs-WARNING **: Deprecated function.  User modifications to the
MIME database are no longer supported.

This update disables the "setDefaultBrowser" option. Red Hat Enterprise
Linux 4 users wishing to set a default web browser can use Applications ->
Preferences -> More Preferences -> Preferred Applications. Red Hat
Enterprise Linux 5 users can use System -> Preferences -> Preferred
Applications. (BZ#463131, BZ#665031)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.14, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1585.html">CVE-2010-1585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0051.html">CVE-2011-0051</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0053.html">CVE-2011-0053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0054.html">CVE-2011-0054</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0055.html">CVE-2011-0055</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0056.html">CVE-2011-0056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0057.html">CVE-2011-0057</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0058.html">CVE-2011-0058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0059.html">CVE-2011-0059</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0061.html">CVE-2011-0061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0062.html">CVE-2011-0062</cve>
                <bugzilla href="http://bugzilla.redhat.com/463131" id="463131">libgnomevfs-WARNING when making firefox as default browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665031" id="665031">firefox -setDefaultBrowser throws warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675082" id="675082">CVE-2011-0053 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675083" id="675083">CVE-2011-0062 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675087" id="675087">CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675090" id="675090">CVE-2011-0055 Mozilla use-after-free error in JSON.stringify (MFSA2011-03)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675091" id="675091">CVE-2011-0054 Mozilla Buffer overflow in JavaScript upvarMap (MFSA 2011-04)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675092" id="675092">CVE-2011-0056 Mozilla Buffer overflow in JavaScript atom map (MFSA 2011-05)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675093" id="675093">CVE-2011-0057 Mozilla use-after-free error using Web Workers (MFSA 2011-06)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675094" id="675094">CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675095" id="675095">CVE-2011-0061 Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675143" id="675143">CVE-2011-0058 Mozilla memory corruption during text run construction (MFSA 2011-07)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681369" id="681369">CVE-2011-0059 Mozilla CSRF risk with plugins and 307 redirects (MFSA 2011-10)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310002" comment="xulrunner is earlier than 0:1.9.2.14-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310004" comment="xulrunner-devel is earlier than 0:1.9.2.14-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310006" comment="firefox is earlier than 0:3.6.14-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310006" comment="firefox is earlier than 0:3.6.14-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310013" comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310015" comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310013" comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310015" comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310019" comment="firefox is earlier than 0:3.6.14-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110310019" comment="firefox is earlier than 0:3.6.14-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310023" comment="firefox is earlier than 0:3.6.14-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110311" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0311: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0311-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0311.html" />
          <reference source="CVE" ref_id="CVE-2010-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1585.html" />
          <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html" />
          <reference source="CVE" ref_id="CVE-2011-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0061.html" />
          <reference source="CVE" ref_id="CVE-2011-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0062.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2010-1585, CVE-2011-0053, CVE-2011-0062)

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-0061)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1585.html">CVE-2010-1585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0053.html">CVE-2011-0053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0061.html">CVE-2011-0061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0062.html">CVE-2011-0062</cve>
                <bugzilla href="http://bugzilla.redhat.com/675082" id="675082">CVE-2011-0053 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675083" id="675083">CVE-2011-0062 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675094" id="675094">CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675095" id="675095">CVE-2011-0061 Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110311005" comment="thunderbird is earlier than 0:3.1.8-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110312" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0312: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0312-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0312.html" />
          <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html" />
          <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0051, CVE-2011-0053)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0051.html">CVE-2011-0051</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0053.html">CVE-2011-0053</cve>
                <bugzilla href="http://bugzilla.redhat.com/675082" id="675082">CVE-2011-0053 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675087" id="675087">CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312002" comment="thunderbird is earlier than 0:2.0.0.24-14.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312005" comment="thunderbird is earlier than 0:1.5.0.12-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110313" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0313: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0313-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0313.html" />
          <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html" />
          <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html" />
          <reference source="CVE" ref_id="CVE-2011-0059" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0059.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled dialog boxes. An attacker
could use this flaw to create a malicious web page that would present a
blank dialog box that has non-functioning buttons. If a user closes the
dialog box window, it could unexpectedly grant the malicious web page
elevated privileges. (CVE-2011-0051)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-0053)

A flaw was found in the way SeaMonkey handled plug-ins that perform HTTP
requests. If a plug-in performed an HTTP request, and the server sent a 307
redirect response, the plug-in was not notified, and the HTTP request was
forwarded. The forwarded request could contain custom headers, which could
result in a Cross Site Request Forgery attack. (CVE-2011-0059)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-01" />
        <updated date="2011-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0051.html">CVE-2011-0051</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0053.html">CVE-2011-0053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0059.html">CVE-2011-0059</cve>
                <bugzilla href="http://bugzilla.redhat.com/675082" id="675082">CVE-2011-0053 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675087" id="675087">CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681369" id="681369">CVE-2011-0059 Mozilla CSRF risk with plugins and 307 redirects (MFSA 2011-10)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313010" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313008" comment="seamonkey-mail is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313002" comment="seamonkey is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313006" comment="seamonkey-devel is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313012" comment="seamonkey-chat is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110313004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-67.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110318" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0318: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0318-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0318.html" />
          <reference source="CVE" ref_id="CVE-2011-0192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0192.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF Internet Fax image files, compressed with the CCITT Group 4
compression algorithm. An attacker could use this flaw to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2011-0192)

Red Hat would like to thank Apple Product Security for reporting this
issue.

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications linked
against libtiff must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-02" />
        <updated date="2011-03-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0192.html">CVE-2011-0192</cve>
                <bugzilla href="http://bugzilla.redhat.com/678635" id="678635">CVE-2011-0192 libtiff: buffer overflow in Fax4Decode</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318002" comment="libtiff is earlier than 0:3.8.2-7.el5_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318003" comment="libtiff is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318004" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318005" comment="libtiff-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318012" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318013" comment="libtiff-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318010" comment="libtiff is earlier than 0:3.9.4-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318011" comment="libtiff is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318014" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318015" comment="libtiff-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318017" comment="libtiff is earlier than 0:3.6.1-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318018" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110318019" comment="libtiff-devel is earlier than 0:3.6.1-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318020" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110320" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0320: libcgroup security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0320-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0320.html" />
          <reference source="CVE" ref_id="CVE-2011-1006" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1006.html" />
          <reference source="CVE" ref_id="CVE-2011-1022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1022.html" />
    
    <description>The libcgroup packages provide tools and libraries to control and monitor
control groups.

A heap-based buffer overflow flaw was found in the way libcgroup converted
a list of user-provided controllers for a particular task into an array of
strings. A local attacker could use this flaw to escalate their privileges
via a specially-crafted list of controllers. (CVE-2011-1006)

It was discovered that libcgroup did not properly check the origin of
Netlink messages. A local attacker could use this flaw to send crafted
Netlink messages to the cgrulesengd daemon, causing it to put processes
into one or more existing control groups, based on the attacker's choosing,
possibly allowing the particular tasks to run with more resources (memory,
CPU, etc.) than originally intended. (CVE-2011-1022)

Red Hat would like to thank Nelson Elhage for reporting the CVE-2011-1006
issue.

All libcgroup users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-03" />
        <updated date="2011-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1006.html">CVE-2011-1006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1022.html">CVE-2011-1022</cve>
                <bugzilla href="http://bugzilla.redhat.com/678107" id="678107">CVE-2011-1006 libcgroup: Heap-based buffer overflow by converting list of controllers for given task into an array of strings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680409" id="680409">CVE-2011-1022 libcgroup: Uncheck origin of NETLINK messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110320009" comment="libcgroup-pam is earlier than 0:0.36.1-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110320010" comment="libcgroup-pam is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110320007" comment="libcgroup-devel is earlier than 0:0.36.1-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110320008" comment="libcgroup-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110320005" comment="libcgroup is earlier than 0:0.36.1-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110320006" comment="libcgroup is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110324" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0324: logwatch security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0324.html" />
          <reference source="CVE" ref_id="CVE-2011-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1018.html" />
    
    <description>Logwatch is a customizable log analysis system. Logwatch parses through
your system's logs for a given period of time and creates a report
analyzing areas that you specify, in as much detail as you require.

A flaw was found in the way Logwatch processed log files. If an attacker
were able to create a log file with a malicious file name, it could result
in arbitrary code execution with the privileges of the root user when that
log file is analyzed by Logwatch. (CVE-2011-1018)

Users of logwatch should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-07" />
        <updated date="2011-03-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1018.html">CVE-2011-1018</cve>
                <bugzilla href="http://bugzilla.redhat.com/680237" id="680237">CVE-2011-1018 logwatch: Privilege escalation due improper sanitization of special characters in log file names</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110324002" comment="logwatch is earlier than 0:7.3-9.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110324003" comment="logwatch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110324008" comment="logwatch is earlier than 0:7.3.6-49.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110324009" comment="logwatch is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110327" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0327: subversion security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0327.html" />
          <reference source="CVE" ref_id="CVE-2011-0715" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0715.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests to lock working copy paths in a repository. A
remote attacker could issue a lock request that could cause the httpd
process serving the request to crash. (CVE-2011-0715)

Red Hat would like to thank Hyrum Wright of the Apache Subversion project
for reporting this issue. Upstream acknowledges Philip Martin, WANdisco,
Inc. as the original reporter.

This update also fixes the following bug:

* A regression was found in the handling of repositories which do not have
a "db/fsfs.conf" file. The "svnadmin hotcopy" command would fail when
trying to produce a copy of such a repository. This command has been fixed
to ignore the absence of the "fsfs.conf" file. The "svnadmin hotcopy"
command will now succeed for this type of repository. (BZ#681522)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-08" />
        <updated date="2011-03-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0715.html">CVE-2011-0715</cve>
                <bugzilla href="http://bugzilla.redhat.com/680755" id="680755">CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681522" id="681522">Regression: svnadmin hotcopy throws error</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327006" comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257007" comment="subversion-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327002" comment="subversion is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257003" comment="subversion is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327012" comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257013" comment="subversion-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327004" comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257009" comment="subversion-ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327008" comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257011" comment="subversion-javahl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110327010" comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257005" comment="mod_dav_svn is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110328" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0328: subversion security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0328-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0328.html" />
          <reference source="CVE" ref_id="CVE-2011-0715" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0715.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed certain requests to lock working copy paths in a repository. A
remote attacker could issue a lock request that could cause the httpd
process serving the request to crash. (CVE-2011-0715)

Red Hat would like to thank Hyrum Wright of the Apache Subversion project
for reporting this issue. Upstream acknowledges Philip Martin, WANdisco,
Inc. as the original reporter.

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-08" />
        <updated date="2011-03-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0715.html">CVE-2011-0715</cve>
                <bugzilla href="http://bugzilla.redhat.com/680755" id="680755">CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328007" comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258020" comment="subversion-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328009" comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258010" comment="subversion-kde is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328005" comment="subversion is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258006" comment="subversion is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328021" comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258018" comment="subversion-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328019" comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258008" comment="subversion-ruby is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328013" comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258016" comment="subversion-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328017" comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258022" comment="subversion-javahl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328015" comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258014" comment="mod_dav_svn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110328011" comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258012" comment="subversion-svn2cl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110329" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0329: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0329-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0329.html" />
          <reference source="CVE" ref_id="CVE-2011-0714" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0714.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issue:

* A use-after-free flaw was found in the Linux kernel's RPC server sockets
implementation. A remote attacker could use this flaw to trigger a denial
of service by sending a corrupted packet to a target system.
(CVE-2011-0714, Important)

Red Hat would like to thank Adam Prince for reporting this issue.

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The system must be rebooted for this update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-08" />
        <updated date="2011-03-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0714.html">CVE-2011-0714</cve>
                <bugzilla href="http://bugzilla.redhat.com/678144" id="678144">CVE-2011-0714 kernel: deficiency in handling of invalid data packets in lockd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329021" comment="kernel-firmware is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329007" comment="kernel-headers is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329005" comment="kernel is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329025" comment="kernel-doc is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329015" comment="kernel-devel is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329023" comment="perf is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329013" comment="kernel-debug is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329017" comment="kernel-kdump is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329011" comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329019" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110329009" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110332" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0332: scsi-target-utils security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0332.html" />
          <reference source="CVE" ref_id="CVE-2011-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0001.html" />
    
    <description>The scsi-target-utils package contains the daemon and tools to set up and
monitor SCSI targets. Currently, iSCSI software and iSER targets are
supported.

A double-free flaw was found in scsi-target-utils' tgtd daemon. A remote
attacker could trigger this flaw by sending carefully-crafted network
traffic, causing the tgtd daemon to crash. (CVE-2011-0001)

Red Hat would like to thank Emmanuel Bouillon of NATO C3 Agency for
reporting this issue.

All scsi-target-utils users should upgrade to this updated package, which
contains a backported patch to correct this issue. All running
scsi-target-utils services must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-09" />
        <updated date="2011-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0001.html">CVE-2011-0001</cve>
                <bugzilla href="http://bugzilla.redhat.com/667261" id="667261">CVE-2011-0001 scsi-target-utils: double-free vulnerability leads to pre-authenticated crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_cluster_storage</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110332002" comment="scsi-target-utils is earlier than 0:1.0.8-0.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110332003" comment="scsi-target-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110332008" comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110332009" comment="scsi-target-utils is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110335" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0335: tomcat6 security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0335-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0335.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
          <reference source="CVE" ref_id="CVE-2011-0534" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0534.html" />
    
    <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Tomcat to hang via a specially-crafted HTTP request. (CVE-2010-4476)

A flaw was found in the Tomcat NIO (Non-Blocking I/O) connector. A remote
attacker could use this flaw to cause a denial of service (out-of-memory
condition) via a specially-crafted request containing a large NIO buffer
size request value. (CVE-2011-0534)

This update also fixes the following bug:

* A bug in the "tomcat6" init script prevented additional Tomcat instances
from starting. As well, running "service tomcat6 start" caused
configuration options applied from "/etc/sysconfig/tomcat6" to be
overwritten with those from "/etc/tomcat6/tomcat6.conf". With this update,
multiple instances of Tomcat run as expected. (BZ#676922)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-09" />
        <updated date="2011-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0534.html">CVE-2011-0534</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675338" id="675338">CVE-2011-0534 tomcat: remote DoS via NIO connector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676922" id="676922">Additionally Created Instances of Tomcat  are broken / don't work</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335005" comment="tomcat6 is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335006" comment="tomcat6 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335023" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335024" comment="tomcat6-el-2.1-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335021" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335022" comment="tomcat6-admin-webapps is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335015" comment="tomcat6-log4j is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335016" comment="tomcat6-log4j is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335019" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335020" comment="tomcat6-docs-webapp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335013" comment="tomcat6-webapps is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335014" comment="tomcat6-webapps is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335011" comment="tomcat6-javadoc is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335012" comment="tomcat6-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335007" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335008" comment="tomcat6-jsp-2.1-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335009" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335010" comment="tomcat6-servlet-2.5-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110335017" comment="tomcat6-lib is earlier than 0:6.0.24-24.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335018" comment="tomcat6-lib is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110336" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0336: tomcat5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0336.html" />
          <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html" />
    
    <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A denial of service flaw was found in the way certain strings were
converted to Double objects. A remote attacker could use this flaw to cause
Tomcat to hang via a specially-crafted HTTP request. (CVE-2010-4476)

Users of Tomcat should upgrade to these updated packages, which contain a
backported patch to correct this issue. Tomcat must be restarted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-09" />
        <updated date="2011-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4476.html">CVE-2010-4476</cve>
                <bugzilla href="http://bugzilla.redhat.com/674336" id="674336">CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336020" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336021" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336016" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336017" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336012" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336013" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336018" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336019" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336014" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336015" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336022" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336023" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336010" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336011" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336008" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336009" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336006" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336007" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336004" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336005" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110336002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110336003" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110337" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0337: vsftpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0337.html" />
          <reference source="CVE" ref_id="CVE-2011-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0762.html" />
    
    <description>vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux, UNIX, and similar operating systems.

A flaw was discovered in the way vsftpd processed file name patterns. An
FTP user could use this flaw to cause the vsftpd process to use an
excessive amount of CPU time, when processing a request with a
specially-crafted file name pattern. (CVE-2011-0762)

All vsftpd users should upgrade to this updated package, which contains a
backported patch to correct this issue. The vsftpd daemon must be restarted
for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-09" />
        <updated date="2011-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0762.html">CVE-2011-0762</cve>
                <bugzilla href="http://bugzilla.redhat.com/681667" id="681667">CVE-2011-0762 vsftpd: remote DoS via crafted glob pattern</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110337002" comment="vsftpd is earlier than 0:2.0.5-16.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110337003" comment="vsftpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110337008" comment="vsftpd is earlier than 0:2.2.2-6.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110337009" comment="vsftpd is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110337011" comment="vsftpd is earlier than 0:2.0.1-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110337012" comment="vsftpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110345" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0345: qemu-kvm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0345-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0345.html" />
          <reference source="CVE" ref_id="CVE-2011-0011" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0011.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM. Virtual Network Computing (VNC) is
a remote display system.

A flaw was found in the way the VNC "password" option was handled. Clearing
a password disabled VNC authentication, allowing a remote user able to
connect to the virtual machines' VNC ports to open a VNC session without
authentication. (CVE-2011-0011)

All users of qemu-kvm should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-10" />
        <updated date="2011-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0011.html">CVE-2011-0011</cve>
                <bugzilla href="http://bugzilla.redhat.com/668589" id="668589">CVE-2011-0011 qemu-kvm: Setting VNC password to empty string silently disables all authentication</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110345009" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.113.el6_0.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345010" comment="qemu-kvm-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110345005" comment="qemu-kvm is earlier than 2:0.12.1.2-2.113.el6_0.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345006" comment="qemu-kvm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110345007" comment="qemu-img is earlier than 2:0.12.1.2-2.113.el6_0.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345008" comment="qemu-img is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110346" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0346: openldap security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0346.html" />
          <reference source="CVE" ref_id="CVE-2011-1024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1024.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled authentication failures being
passed from an OpenLDAP slave to the master. If OpenLDAP was configured
with a chain overlay and it forwarded authentication failures, OpenLDAP
would bind to the directory as an anonymous user and return success, rather
than return failure on the authenticated bind. This could allow a user on a
system that uses LDAP for authentication to log into a directory-based
account without knowing the password. (CVE-2011-1024)

This update also fixes the following bug:

* Previously, multiple concurrent connections to an OpenLDAP server could
cause the slapd service to terminate unexpectedly with an assertion error.
This update adds mutexes to protect multiple threads from accessing a
structure with a connection, and the slapd service no longer crashes.
(BZ#677611)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-10" />
        <updated date="2011-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1024.html">CVE-2011-1024</cve>
                <bugzilla href="http://bugzilla.redhat.com/680466" id="680466">CVE-2011-1024 openldap: forwarded bind failure messages cause success</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346004" comment="openldap-devel is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346005" comment="openldap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346006" comment="openldap-clients is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346007" comment="openldap-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346012" comment="openldap-servers-sql is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346013" comment="openldap-servers-sql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346014" comment="compat-openldap is earlier than 0:2.3.43_2.2.29-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346015" comment="compat-openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346002" comment="openldap is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346003" comment="openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346008" comment="openldap-servers is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346009" comment="openldap-servers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110346010" comment="openldap-servers-overlays is earlier than 0:2.3.43-12.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110346011" comment="openldap-servers-overlays is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110347" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0347: openldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0347-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0347.html" />
          <reference source="CVE" ref_id="CVE-2011-1024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1024.html" />
          <reference source="CVE" ref_id="CVE-2011-1025" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1025.html" />
          <reference source="CVE" ref_id="CVE-2011-1081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1081.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled authentication failures being
passed from an OpenLDAP slave to the master. If OpenLDAP was configured
with a chain overlay and it forwarded authentication failures, OpenLDAP
would bind to the directory as an anonymous user and return success, rather
than return failure on the authenticated bind. This could allow a user on a
system that uses LDAP for authentication to log into a directory-based
account without knowing the password. (CVE-2011-1024)

It was found that the OpenLDAP back-ndb back end allowed successful
authentication to the root distinguished name (DN) when any string was
provided as a password. A remote user could use this flaw to access an
OpenLDAP directory if they knew the value of the root DN. Note: This issue
only affected OpenLDAP installations using the NDB back-end, which is only
available for Red Hat Enterprise Linux 6 via third-party software.
(CVE-2011-1025)

A flaw was found in the way OpenLDAP handled modify relative distinguished
name (modrdn) requests. A remote, unauthenticated user could use this flaw
to crash an OpenLDAP server via a modrdn request containing an empty old
RDN value. (CVE-2011-1081)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-10" />
        <updated date="2011-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1024.html">CVE-2011-1024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1025.html">CVE-2011-1025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1081.html">CVE-2011-1081</cve>
                <bugzilla href="http://bugzilla.redhat.com/680466" id="680466">CVE-2011-1024 openldap: forwarded bind failure messages cause success</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680472" id="680472">CVE-2011-1025 openldap: rootpw not verified via slapd.conf when using the NDB backend</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680975" id="680975">CVE-2011-1081 openldap: DoS when submitting special MODRDN request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347007" comment="openldap-devel is earlier than 0:2.4.19-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347008" comment="openldap-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347015" comment="openldap-clients is earlier than 0:2.4.19-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347016" comment="openldap-clients is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347013" comment="openldap-servers-sql is earlier than 0:2.4.19-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347014" comment="openldap-servers-sql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347009" comment="compat-openldap is earlier than 0:2.4.19_2.3.43-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347010" comment="compat-openldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347005" comment="openldap is earlier than 0:2.4.19-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347006" comment="openldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110347011" comment="openldap-servers is earlier than 0:2.4.19-15.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110347012" comment="openldap-servers is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110356" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0356: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0356-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0356.html" />
          <reference source="CVE" ref_id="CVE-2011-0284" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0284.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC). The Public Key
Cryptography for Initial Authentication in Kerberos (PKINIT) capability
provides support for using public-key authentication with Kerberos.

A double-free flaw was found in the way the MIT Kerberos KDC handled
initial authentication requests (AS-REQ), when the KDC was configured to
provide the PKINIT capability. A remote attacker could use this flaw to
cause the KDC daemon to abort by using a specially-crafted AS-REQ request.
(CVE-2011-0284)

All krb5 users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-16" />
        <updated date="2011-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0284.html">CVE-2011-0284</cve>
                <bugzilla href="http://bugzilla.redhat.com/674325" id="674325">CVE-2011-0284 krb5 (krb5kdc): Double-free flaw by handling error messages upon receiving certain AS_REQ's (MITKRB5-SA-2011-003)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356017" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200008" comment="krb5-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356007" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200016" comment="krb5-pkinit-openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356011" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200014" comment="krb5-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356009" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200018" comment="krb5-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356013" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200012" comment="krb5-server-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356005" comment="krb5 is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200006" comment="krb5 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110356015" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200010" comment="krb5-workstation is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110357" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0357: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0357.html" />
          <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html" />
          <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html" />
          <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html" />
          <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html" />
          <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html" />
          <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html" />
          <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html" />
          <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html" />
          <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html" />
          <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html" />
          <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html" />
          <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html" />
          <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html" />
          <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2010-4422, CVE-2010-4447,
CVE-2010-4448, CVE-2010-4452, CVE-2010-4454, CVE-2010-4462, CVE-2010-4463,
CVE-2010-4465, CVE-2010-4466, CVE-2010-4467, CVE-2010-4468, CVE-2010-4471,
CVE-2010-4473, CVE-2010-4475)

Note: The RHSA-2010:0987 and RHSA-2011:0290 java-1.6.0-ibm errata were
missing 64-bit PowerPC packages for Red Hat Enterprise Linux 4 Extras. This
erratum provides 64-bit PowerPC packages for Red Hat Enterprise Linux 4
Extras as expected.

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR9-FP1 Java release. All running
instances of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-16" />
        <updated date="2011-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4422.html">CVE-2010-4422</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4447.html">CVE-2010-4447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4448.html">CVE-2010-4448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4452.html">CVE-2010-4452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4454.html">CVE-2010-4454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4462.html">CVE-2010-4462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4463.html">CVE-2010-4463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4465.html">CVE-2010-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4466.html">CVE-2010-4466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4467.html">CVE-2010-4467</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4468.html">CVE-2010-4468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4471.html">CVE-2010-4471</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4473.html">CVE-2010-4473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4475.html">CVE-2010-4475</cve>
                <bugzilla href="http://bugzilla.redhat.com/675984" id="675984">CVE-2010-4465 OpenJDK Swing timer-based security manager bypass  (6907662)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676019" id="676019">CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676023" id="676023">CVE-2010-4448 OpenJDK DNS cache poisoning by untrusted applets (6981922)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677957" id="677957">CVE-2010-4475 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677958" id="677958">CVE-2010-4473 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677959" id="677959">CVE-2010-4468 JDK unspecified vulnerability in JDBC component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677960" id="677960">CVE-2010-4467 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677961" id="677961">CVE-2010-4466 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677963" id="677963">CVE-2010-4463 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677966" id="677966">CVE-2010-4462 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677967" id="677967">CVE-2010-4454 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677968" id="677968">CVE-2010-4452 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677970" id="677970">CVE-2010-4447 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677971" id="677971">CVE-2010-4422 JDK unspecified vulnerability in Deployment component</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357008" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290013" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357016" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290005" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357012" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357014" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290011" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357004" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290015" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357006" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290017" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357010" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290007" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357032" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290029" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357022" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290023" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357026" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290033" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357030" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290035" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357028" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290027" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357034" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290031" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110357024" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290025" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110364" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0364-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0364.html" />
          <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html" />
          <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html" />
          <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html" />
          <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html" />
          <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html" />
          <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html" />
          <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html" />
          <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html" />
          <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html" />
          <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html" />
          <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2010-4447, CVE-2010-4448,
CVE-2010-4450, CVE-2010-4454, CVE-2010-4462, CVE-2010-4465, CVE-2010-4466,
CVE-2010-4468, CVE-2010-4471, CVE-2010-4473, CVE-2010-4475)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR12-FP4 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-17" />
        <updated date="2011-03-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4447.html">CVE-2010-4447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4448.html">CVE-2010-4448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4450.html">CVE-2010-4450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4454.html">CVE-2010-4454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4462.html">CVE-2010-4462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4465.html">CVE-2010-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4466.html">CVE-2010-4466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4468.html">CVE-2010-4468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4471.html">CVE-2010-4471</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4473.html">CVE-2010-4473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4475.html">CVE-2010-4475</cve>
                <bugzilla href="http://bugzilla.redhat.com/675984" id="675984">CVE-2010-4465 OpenJDK Swing timer-based security manager bypass  (6907662)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676019" id="676019">CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676023" id="676023">CVE-2010-4448 OpenJDK DNS cache poisoning by untrusted applets (6981922)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676026" id="676026">CVE-2010-4450 OpenJDK Launcher incorrect processing of empty library path entries  (6983554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677957" id="677957">CVE-2010-4475 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677958" id="677958">CVE-2010-4473 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677959" id="677959">CVE-2010-4468 JDK unspecified vulnerability in JDBC component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677961" id="677961">CVE-2010-4466 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677966" id="677966">CVE-2010-4462 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677967" id="677967">CVE-2010-4454 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677970" id="677970">CVE-2010-4447 JDK unspecified vulnerability in Deployment component</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364008" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169009" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364010" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169005" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364016" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169007" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364006" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169017" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364012" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364014" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169011" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364024" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169035" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364022" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169023" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364026" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169031" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364032" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169027" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364028" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169029" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364034" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169033" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110364030" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169025" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110369" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0369: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0369-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0369.html" />
          <reference source="CVE" ref_id="CVE-2011-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0444.html" />
          <reference source="CVE" ref_id="CVE-2011-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0538.html" />
          <reference source="CVE" ref_id="CVE-2011-0713" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0713.html" />
          <reference source="CVE" ref_id="CVE-2011-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1139.html" />
          <reference source="CVE" ref_id="CVE-2011-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1140.html" />
          <reference source="CVE" ref_id="CVE-2011-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1141.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A heap-based buffer overflow flaw was found in the Wireshark MAC-LTE
dissector. If Wireshark read a malformed packet off a network or opened a
malicious dump file, it could crash or, possibly, execute arbitrary code as
the user running Wireshark. (CVE-2011-0444)

A heap-based buffer overflow flaw was found in the way Wireshark processed
signaling traces generated by the Gammu utility on Nokia DCT3 phones
running in Netmonitor mode. If Wireshark opened a specially-crafted capture
file, it could crash or, possibly, execute arbitrary code as the user
running Wireshark. (CVE-2011-0713)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2011-0538, CVE-2011-1139, CVE-2011-1140,
CVE-2011-1141)

Users of Wireshark should upgrade to these updated packages, which contain
Wireshark version 1.2.15, and resolve these issues. All running instances
of Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-21" />
        <updated date="2011-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0444.html">CVE-2011-0444</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0538.html">CVE-2011-0538</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0713.html">CVE-2011-0713</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1139.html">CVE-2011-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1140.html">CVE-2011-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1141.html">CVE-2011-1141</cve>
                <bugzilla href="http://bugzilla.redhat.com/669441" id="669441">CVE-2011-0444 wireshark: buffer overflow in MAC-LTE disector (upstream bug #5530)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676232" id="676232">CVE-2011-0538 Wireshark: memory corruption when reading a malformed pcap file (upstream bug #5652)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678198" id="678198">CVE-2011-0713 Wireshark: heap-based buffer overflow when reading malformed Nokia DCT3 phone signalling traces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681748" id="681748">CVE-2011-1139 Wireshark: Denial Of Service (application crash) via a pcap-ng file that contains a large packet-length field</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681754" id="681754">CVE-2011-1140 Wireshark: Multiple stack consumption vulnerabilities caused DoS via crafted SMB or CLDAP packet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681756" id="681756">CVE-2011-1141 Wireshark: Malformed LDAP filter string causes Denial of Service via excessive memory consumption</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110369007" comment="wireshark-devel is earlier than 0:1.2.15-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013015" comment="wireshark-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110369005" comment="wireshark is earlier than 0:1.2.15-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013011" comment="wireshark is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110369009" comment="wireshark-gnome is earlier than 0:1.2.15-1.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013013" comment="wireshark-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110370" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0370: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0370-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0370.html" />
          <reference source="CVE" ref_id="CVE-2010-3445" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3445.html" />
          <reference source="CVE" ref_id="CVE-2011-0024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0024.html" />
          <reference source="CVE" ref_id="CVE-2011-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0538.html" />
          <reference source="CVE" ref_id="CVE-2011-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1139.html" />
          <reference source="CVE" ref_id="CVE-2011-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1140.html" />
          <reference source="CVE" ref_id="CVE-2011-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1141.html" />
          <reference source="CVE" ref_id="CVE-2011-1143" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1143.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A heap-based buffer overflow flaw was found in Wireshark. If Wireshark
opened a specially-crafted capture file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2011-0024)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2010-3445, CVE-2011-0538, CVE-2011-1139,
CVE-2011-1140, CVE-2011-1141, CVE-2011-1143)

Users of Wireshark should upgrade to these updated packages, which contain
backported patches to correct these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-21" />
        <updated date="2011-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3445.html">CVE-2010-3445</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0024.html">CVE-2011-0024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0538.html">CVE-2011-0538</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1139.html">CVE-2011-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1140.html">CVE-2011-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1141.html">CVE-2011-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1143.html">CVE-2011-1143</cve>
                <bugzilla href="http://bugzilla.redhat.com/639486" id="639486">CVE-2010-3445 wireshark: stack overflow in BER dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671331" id="671331">CVE-2011-0024 heap-based buffer overflow in wireshark &lt; 1.2 when reading malformed capture files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676232" id="676232">CVE-2011-0538 Wireshark: memory corruption when reading a malformed pcap file (upstream bug #5652)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681748" id="681748">CVE-2011-1139 Wireshark: Denial Of Service (application crash) via a pcap-ng file that contains a large packet-length field</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681754" id="681754">CVE-2011-1140 Wireshark: Multiple stack consumption vulnerabilities caused DoS via crafted SMB or CLDAP packet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681756" id="681756">CVE-2011-1141 Wireshark: Malformed LDAP filter string causes Denial of Service via excessive memory consumption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681760" id="681760">CVE-2011-1143 Wireshark: Null pointer dereference causing application crash when reading malformed pcap file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110370002" comment="wireshark is earlier than 0:1.0.15-1.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110370004" comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110370007" comment="wireshark is earlier than 0:1.0.15-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013018" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110370009" comment="wireshark-gnome is earlier than 0:1.0.15-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110013020" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110372" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0372: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0372-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0372.html" />
          <reference source="CVE" ref_id="CVE-2011-0609" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0609.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed on the Adobe security page APSB11-05, listed in
the References section. Specially-crafted SWF content could cause
flash-plugin to crash or, potentially, execute arbitrary code.
(CVE-2011-0609)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.2.153.1.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-22" />
        <updated date="2011-03-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0609.html">CVE-2011-0609</cve>
                <bugzilla href="http://bugzilla.redhat.com/684988" id="684988">CVE-2011-0609 flash-plugin: crash and potential arbitrary code execution (APSB11-05)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372002" comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110372008" comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110373" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0373: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0373.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-22" />
        <updated date="2011-03-22" />
                <bugzilla href="http://bugzilla.redhat.com/689430" id="689430">Compromised certificates</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110373002" comment="xulrunner is earlier than 0:1.9.2.15-2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110373004" comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110373010" comment="xulrunner is earlier than 0:1.9.2.15-2.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110373012" comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110373015" comment="firefox is earlier than 0:3.6.15-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110374" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0374: thunderbird security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0374-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0374.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

This update also fixes the following bug:

* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-22" />
        <updated date="2011-03-22" />
                <bugzilla href="http://bugzilla.redhat.com/683076" id="683076">Mozilla 3.6.14 regression [rhel-6.1]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689430" id="689430">Compromised certificates</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110374002" comment="thunderbird is earlier than 0:2.0.0.24-15.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110374008" comment="thunderbird is earlier than 0:3.1.9-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110374011" comment="thunderbird is earlier than 0:1.5.0.12-36.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110375" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0375: seamonkey security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0375-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0375.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-22" />
        <updated date="2011-03-22" />
                <bugzilla href="http://bugzilla.redhat.com/689430" id="689430">Compromised certificates</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375010" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375008" comment="seamonkey-mail is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375002" comment="seamonkey is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375012" comment="seamonkey-devel is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375004" comment="seamonkey-chat is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110375006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-68.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110376" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0376: dbus security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0376.html" />
          <reference source="CVE" ref_id="CVE-2010-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4352.html" />
    
    <description>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial of service flaw was discovered in the system for sending messages
between applications. A local user could send a message with an excessive
number of nested variants to the system-wide message bus, causing the
message bus (and, consequently, any process using libdbus to receive
messages) to abort. (CVE-2010-4352)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-22" />
        <updated date="2011-03-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4352.html">CVE-2010-4352</cve>
                <bugzilla href="http://bugzilla.redhat.com/663673" id="663673">CVE-2010-4352 D-BUS: Stack overflow by validating message with excessive number of nested variants</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376004" comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376005" comment="dbus-x11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376008" comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376009" comment="dbus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376002" comment="dbus is earlier than 0:1.1.2-15.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376003" comment="dbus is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376006" comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376007" comment="dbus-libs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376022" comment="dbus-x11 is earlier than 1:1.2.24-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376023" comment="dbus-x11 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376018" comment="dbus-doc is earlier than 1:1.2.24-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376019" comment="dbus-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376016" comment="dbus-devel is earlier than 1:1.2.24-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376017" comment="dbus-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376014" comment="dbus is earlier than 1:1.2.24-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376015" comment="dbus is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110376020" comment="dbus-libs is earlier than 1:1.2.24-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376021" comment="dbus-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110390" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0390: rsync security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0390-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0390.html" />
          <reference source="CVE" ref_id="CVE-2011-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1097.html" />
    
    <description>rsync is a program for synchronizing files over a network.

A memory corruption flaw was found in the way the rsync client processed
malformed file list data. If an rsync client used the "--recursive" and
"--delete" options without the "--owner" option when connecting to a
malicious rsync server, the malicious server could cause rsync on the
client system to crash or, possibly, execute arbitrary code with the
privileges of the user running rsync. (CVE-2011-1097)

Red Hat would like to thank Wayne Davison and Matt McCutchen for reporting
this issue.

Users of rsync should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-28" />
        <updated date="2011-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1097.html">CVE-2011-1097</cve>
                <bugzilla href="http://bugzilla.redhat.com/675036" id="675036">CVE-2011-1097 rsync: Incremental file-list corruption due to temporary file_extra_cnt increments</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110390005" comment="rsync is earlier than 0:3.0.6-5.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110390006" comment="rsync is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110391" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0391: libvirt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0391.html" />
          <reference source="CVE" ref_id="CVE-2011-1146" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1146.html" />
    
    <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

It was found that several libvirt API calls did not honor the read-only
permission for connections. A local attacker able to establish a read-only
connection to libvirtd on a server could use this flaw to execute commands
that should be restricted to read-write connections, possibly leading to a
denial of service or privilege escalation. (CVE-2011-1146)

Note: Previously, using rpmbuild without the '--define "rhel 5"' option to
build the libvirt source RPM on Red Hat Enterprise Linux 5 failed with a
"Failed build dependencies" error for the device-mapper-devel package, as
this -devel sub-package is not available on Red Hat Enterprise Linux 5.
With this update, the -devel sub-package is no longer checked by default as
a dependency when building on Red Hat Enterprise Linux 5, allowing the
libvirt source RPM to build as expected.

All libvirt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-28" />
        <updated date="2011-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1146.html">CVE-2011-1146</cve>
                <bugzilla href="http://bugzilla.redhat.com/683650" id="683650">CVE-2011-1146 libvirt: several API calls do not honour read-only connection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391004" comment="libvirt-devel is earlier than 0:0.8.2-15.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391005" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391002" comment="libvirt is earlier than 0:0.8.2-15.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391003" comment="libvirt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391006" comment="libvirt-python is earlier than 0:0.8.2-15.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391007" comment="libvirt-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391014" comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391015" comment="libvirt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391012" comment="libvirt is earlier than 0:0.8.1-27.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391013" comment="libvirt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391018" comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391019" comment="libvirt-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110391016" comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391017" comment="libvirt-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110392" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0392: libtiff security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0392.html" />
          <reference source="CVE" ref_id="CVE-2011-1167" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1167.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF files encoded with a 4-bit run-length encoding scheme from
ThunderScan. An attacker could use this flaw to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2011-1167)

This update also fixes the following bug:

* The RHSA-2011:0318 libtiff update introduced a regression that prevented
certain TIFF Internet Fax image files, compressed with the CCITT Group 4
compression algorithm, from being read. (BZ#688825)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running applications linked
against libtiff must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-28" />
        <updated date="2011-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1167.html">CVE-2011-1167</cve>
                <bugzilla href="http://bugzilla.redhat.com/684939" id="684939">CVE-2011-1167 libtiff: heap-based buffer overflow in thunder decoder (ZDI-11-107)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688825" id="688825">Regression in libtiff due to CVE-2011-0192 fix</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392002" comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318003" comment="libtiff is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392004" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318005" comment="libtiff-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392014" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318013" comment="libtiff-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392010" comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318011" comment="libtiff is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392012" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318015" comment="libtiff-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392017" comment="libtiff is earlier than 0:3.6.1-18.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318018" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110392019" comment="libtiff-devel is earlier than 0:3.6.1-18.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318020" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110394" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0394: conga security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0394-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0394.html" />
          <reference source="CVE" ref_id="CVE-2011-0720" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0720.html" />
    
    <description>The conga packages provide a web-based administration tool for remote
cluster and storage management.

A privilege escalation flaw was found in luci, the Conga web-based
administration application. A remote attacker could possibly use this flaw
to obtain administrative access, allowing them to read, create, or modify
the content of the luci application. (CVE-2011-0720)

Users of Conga are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, luci must be restarted ("service luci restart") for the
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-28" />
        <updated date="2011-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0720.html">CVE-2011-0720</cve>
                <bugzilla href="http://bugzilla.redhat.com/676961" id="676961">CVE-2011-0720 plone: unauthorized remote administrative access</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_cluster</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110394004" comment="ricci is earlier than 0:0.12.2-24.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110394005" comment="ricci is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110394006" comment="luci is earlier than 0:0.12.2-24.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110394007" comment="luci is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110394002" comment="conga is earlier than 0:0.12.2-24.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110394003" comment="conga is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110395" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0395: gdm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0395.html" />
          <reference source="CVE" ref_id="CVE-2011-0727" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0727.html" />
    
    <description>The GNOME Display Manager (GDM) provides the graphical login screen, shown
shortly after boot up, log out, and when user-switching.

A race condition flaw was found in the way GDM handled the cache
directories used to store users' dmrc and face icon files. A local attacker
could use this flaw to trick GDM into changing the ownership of an
arbitrary file via a symbolic link attack, allowing them to escalate their
privileges. (CVE-2011-0727)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

All users should upgrade to these updated packages, which contain a
backported patch to correct this issue. GDM must be restarted for this
update to take effect. Rebooting achieves this, but changing the runlevel
from 5 to 3 and back to 5 also restarts GDM.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-28" />
        <updated date="2011-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0727.html">CVE-2011-0727</cve>
                <bugzilla href="http://bugzilla.redhat.com/688323" id="688323">CVE-2011-0727 gdm: privilege escalation vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110395007" comment="gdm-libs is earlier than 1:2.30.4-21.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110395008" comment="gdm-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110395005" comment="gdm is earlier than 1:2.30.4-21.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110395006" comment="gdm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110395013" comment="gdm-plugin-smartcard is earlier than 1:2.30.4-21.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110395014" comment="gdm-plugin-smartcard is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110395011" comment="gdm-user-switch-applet is earlier than 1:2.30.4-21.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110395012" comment="gdm-user-switch-applet is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110395009" comment="gdm-plugin-fingerprint is earlier than 1:2.30.4-21.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110395010" comment="gdm-plugin-fingerprint is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110406" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0406: quagga security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0406.html" />
          <reference source="CVE" ref_id="CVE-2010-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1674.html" />
          <reference source="CVE" ref_id="CVE-2010-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1675.html" />
    
    <description>Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemon
implements the BGP (Border Gateway Protocol) routing protocol.

A denial of service flaw was found in the way the Quagga bgpd daemon
processed certain route metrics information. A BGP message with a
specially-crafted path limit attribute would cause the bgpd daemon to reset
its session with the peer through which this message was received.
(CVE-2010-1675)

A NULL pointer dereference flaw was found in the way the Quagga bgpd daemon
processed malformed route extended communities attributes. A configured BGP
peer could crash bgpd on a target system via a specially-crafted BGP
message. (CVE-2010-1674)

Users of quagga should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the bgpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-31" />
        <updated date="2011-03-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1674.html">CVE-2010-1674</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1675.html">CVE-2010-1675</cve>
                <bugzilla href="http://bugzilla.redhat.com/654603" id="654603">CVE-2010-1674 quagga: DoS (crash) by processing malformed extended community attribute in a route</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654614" id="654614">CVE-2010-1675 quagga: BGP session reset by processing BGP Update message with malformed AS-path attributes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110406007" comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110406008" comment="quagga-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110406009" comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110406010" comment="quagga-contrib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110406005" comment="quagga is earlier than 0:0.99.15-5.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110406006" comment="quagga is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110407" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0407: logrotate security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0407.html" />
          <reference source="CVE" ref_id="CVE-2011-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1098.html" />
          <reference source="CVE" ref_id="CVE-2011-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1154.html" />
          <reference source="CVE" ref_id="CVE-2011-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1155.html" />
    
    <description>The logrotate utility simplifies the administration of multiple log files,
allowing the automatic rotation, compression, removal, and mailing of log
files.

A shell command injection flaw was found in the way logrotate handled the
shred directive. A specially-crafted log file could cause logrotate to
execute arbitrary commands with the privileges of the user running
logrotate (root, by default). Note: The shred directive is not enabled by
default. (CVE-2011-1154)

A race condition flaw was found in the way logrotate applied permissions
when creating new log files. In some specific configurations, a local
attacker could use this flaw to open new log files before logrotate applies
the final permissions, possibly leading to the disclosure of sensitive
information. (CVE-2011-1098)

An input sanitization flaw was found in logrotate. A log file with a
specially-crafted file name could cause logrotate to abort when attempting
to process that file a subsequent time. (CVE-2011-1155)

All logrotate users should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-03-31" />
        <updated date="2011-03-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1098.html">CVE-2011-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1154.html">CVE-2011-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1155.html">CVE-2011-1155</cve>
                <bugzilla href="http://bugzilla.redhat.com/680796" id="680796">CVE-2011-1154 logrotate: Shell command injection by using the shred configuration directive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680797" id="680797">CVE-2011-1155 logrotate: DoS due improper escaping of file names within 'write state' action</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680798" id="680798">CVE-2011-1098 logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110407005" comment="logrotate is earlier than 0:3.7.8-12.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110407006" comment="logrotate is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110412" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0412: glibc security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0412-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0412.html" />
          <reference source="CVE" ref_id="CVE-2010-0296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0296.html" />
          <reference source="CVE" ref_id="CVE-2011-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0536.html" />
          <reference source="CVE" ref_id="CVE-2011-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1071.html" />
          <reference source="CVE" ref_id="CVE-2011-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1095.html" />
          <reference source="CVE" ref_id="CVE-2011-1658" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1658.html" />
          <reference source="CVE" ref_id="CVE-2011-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1659.html" />
    
    <description>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

The fix for CVE-2010-3847 introduced a regression in the way the dynamic
loader expanded the $ORIGIN dynamic string token specified in the RPATH and
RUNPATH entries in the ELF library header. A local attacker could use this
flaw to escalate their privileges via a setuid or setgid program using
such a library. (CVE-2011-0536)

It was discovered that the glibc addmntent() function did not sanitize its
input properly. A local attacker could possibly use this flaw to inject
malformed lines into /etc/mtab via certain setuid mount helpers, if the
attacker were allowed to mount to an arbitrary directory under their
control. (CVE-2010-0296)

It was discovered that the glibc fnmatch() function did not properly
restrict the use of alloca(). If the function was called on sufficiently
large inputs, it could cause an application using fnmatch() to crash or,
possibly, execute arbitrary code with the privileges of the application.
(CVE-2011-1071)

It was discovered that the locale command did not produce properly escaped
output as required by the POSIX specification. If an attacker were able to
set the locale environment variables in the environment of a script that
performed shell evaluation on the output of the locale command, and that
script were run with different privileges than the attacker's, it could
execute arbitrary code with the privileges of the script. (CVE-2011-1095)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-04" />
        <updated date="2011-04-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0296.html">CVE-2010-0296</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0536.html">CVE-2011-0536</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1071.html">CVE-2011-1071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1095.html">CVE-2011-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1658.html">CVE-2011-1658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1659.html">CVE-2011-1659</cve>
                <bugzilla href="http://bugzilla.redhat.com/559579" id="559579">CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625893" id="625893">CVE-2011-1095 glibc: insufficient quoting in the locale command output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667974" id="667974">CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681054" id="681054">CVE-2011-1071 CVE-2011-1659 glibc: fnmatch() alloca()-based memory corruption flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682991" id="682991">iconv regression</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412012" comment="glibc-common is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412013" comment="glibc-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412008" comment="glibc-headers is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412009" comment="glibc-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412006" comment="glibc-devel is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412007" comment="glibc-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412002" comment="glibc is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412003" comment="glibc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412004" comment="nscd is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412005" comment="nscd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110412010" comment="glibc-utils is earlier than 0:2.5-58.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110412011" comment="glibc-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110413" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0413: glibc security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0413.html" />
          <reference source="CVE" ref_id="CVE-2011-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0536.html" />
          <reference source="CVE" ref_id="CVE-2011-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1071.html" />
          <reference source="CVE" ref_id="CVE-2011-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1095.html" />
          <reference source="CVE" ref_id="CVE-2011-1658" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1658.html" />
          <reference source="CVE" ref_id="CVE-2011-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1659.html" />
    
    <description>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

The fix for CVE-2010-3847 introduced a regression in the way the dynamic
loader expanded the $ORIGIN dynamic string token specified in the RPATH and
RUNPATH entries in the ELF library header. A local attacker could use this
flaw to escalate their privileges via a setuid or setgid program using
such a library. (CVE-2011-0536)

It was discovered that the glibc fnmatch() function did not properly
restrict the use of alloca(). If the function was called on sufficiently
large inputs, it could cause an application using fnmatch() to crash or,
possibly, execute arbitrary code with the privileges of the application.
(CVE-2011-1071)

It was discovered that the locale command did not produce properly escaped
output as required by the POSIX specification. If an attacker were able to
set the locale environment variables in the environment of a script that
performed shell evaluation on the output of the locale command, and that
script were run with different privileges than the attacker's, it could
execute arbitrary code with the privileges of the script. (CVE-2011-1095)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-04" />
        <updated date="2011-04-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0536.html">CVE-2011-0536</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1071.html">CVE-2011-1071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1095.html">CVE-2011-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1658.html">CVE-2011-1658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1659.html">CVE-2011-1659</cve>
                <bugzilla href="http://bugzilla.redhat.com/625893" id="625893">CVE-2011-1095 glibc: insufficient quoting in the locale command output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667974" id="667974">CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681054" id="681054">CVE-2011-1071 CVE-2011-1659 glibc: fnmatch() alloca()-based memory corruption flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413015" comment="glibc-static is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413016" comment="glibc-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413013" comment="glibc-common is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413014" comment="glibc-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413011" comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413012" comment="glibc-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413007" comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413008" comment="glibc-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413005" comment="glibc is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413006" comment="glibc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413009" comment="nscd is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413010" comment="nscd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110413017" comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110413018" comment="glibc-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110414" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0414: policycoreutils security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0414-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0414.html" />
          <reference source="CVE" ref_id="CVE-2011-1011" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1011.html" />
    
    <description>The policycoreutils packages contain the core utilities that are
required for the basic operation of a Security-Enhanced Linux (SELinux)
system and its policies.

It was discovered that the seunshare utility did not enforce proper file
permissions on the directory used as an alternate temporary directory
mounted as /tmp/. A local user could use this flaw to overwrite files or,
possibly, execute arbitrary code with the privileges of a setuid or
setgid application that relies on proper /tmp/ permissions, by running that
application via seunshare. (CVE-2011-1011)

Red Hat would like to thank Tavis Ormandy for reporting this issue.

This update also introduces the following changes:

* The seunshare utility was moved from the main policycoreutils subpackage
to the policycoreutils-sandbox subpackage. This utility is only required
by the sandbox feature and does not need to be installed by default.

* Updated selinux-policy packages that add the SELinux policy changes
required by the seunshare fixes.

All policycoreutils users should upgrade to these updated packages, which
correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-04" />
        <updated date="2011-04-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1011.html">CVE-2011-1011</cve>
                <bugzilla href="http://bugzilla.redhat.com/633544" id="633544">CVE-2011-1011 policycoreutils: insecure temporary directory handling in seunshare</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414007" comment="selinux-policy-minimum is earlier than 0:3.7.19-54.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414008" comment="selinux-policy-minimum is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414011" comment="selinux-policy-targeted is earlier than 0:3.7.19-54.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414012" comment="selinux-policy-targeted is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414009" comment="selinux-policy-mls is earlier than 0:3.7.19-54.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414010" comment="selinux-policy-mls is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414005" comment="selinux-policy is earlier than 0:3.7.19-54.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414006" comment="selinux-policy is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414013" comment="selinux-policy-doc is earlier than 0:3.7.19-54.el6_0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414014" comment="selinux-policy-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414017" comment="policycoreutils-newrole is earlier than 0:2.0.83-19.8.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414018" comment="policycoreutils-newrole is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414023" comment="policycoreutils-gui is earlier than 0:2.0.83-19.8.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414024" comment="policycoreutils-gui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414015" comment="policycoreutils is earlier than 0:2.0.83-19.8.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414016" comment="policycoreutils is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414019" comment="policycoreutils-sandbox is earlier than 0:2.0.83-19.8.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414020" comment="policycoreutils-sandbox is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110414021" comment="policycoreutils-python is earlier than 0:2.0.83-19.8.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110414022" comment="policycoreutils-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110421" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0421: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0421.html" />
          <reference source="CVE" ref_id="CVE-2010-3296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3296.html" />
          <reference source="CVE" ref_id="CVE-2010-4346" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4346.html" />
          <reference source="CVE" ref_id="CVE-2010-4526" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4526.html" />
          <reference source="CVE" ref_id="CVE-2010-4648" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4648.html" />
          <reference source="CVE" ref_id="CVE-2010-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4655.html" />
          <reference source="CVE" ref_id="CVE-2010-4656" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4656.html" />
          <reference source="CVE" ref_id="CVE-2011-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0521.html" />
          <reference source="CVE" ref_id="CVE-2011-0695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0695.html" />
          <reference source="CVE" ref_id="CVE-2011-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0710.html" />
          <reference source="CVE" ref_id="CVE-2011-0716" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0716.html" />
          <reference source="CVE" ref_id="CVE-2011-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1478.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the sctp_icmp_proto_unreachable() function in the
Linux kernel's Stream Control Transmission Protocol (SCTP) implementation.
A remote attacker could use this flaw to cause a denial of service.
(CVE-2010-4526, Important)

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* A race condition was found in the way the Linux kernel's InfiniBand
implementation set up new connections. This could allow a remote user to
cause a denial of service. (CVE-2011-0695, Important)

* A heap overflow flaw in the iowarrior_write() function could allow a
user with access to an IO-Warrior USB device, that supports more than 8
bytes per report, to cause a denial of service or escalate their
privileges. (CVE-2010-4656, Moderate)

* A flaw was found in the way the Linux Ethernet bridge implementation
handled certain IGMP (Internet Group Management Protocol) packets. A local,
unprivileged user on a system that has a network interface in an Ethernet
bridge could use this flaw to crash that system. (CVE-2011-0716, Moderate)

* A NULL pointer dereference flaw was found in the Generic Receive Offload
(GRO) functionality in the Linux kernel's networking implementation. If
both GRO and promiscuous mode were enabled on an interface in a virtual LAN
(VLAN), it could result in a denial of service when a malformed VLAN frame
is received on that interface. (CVE-2011-1478, Moderate)

* A missing initialization flaw in the Linux kernel could lead to an
information leak. (CVE-2010-3296, Low)

* A missing security check in the Linux kernel's implementation of the
install_special_mapping() function could allow a local, unprivileged user
to bypass the mmap_min_addr protection mechanism. (CVE-2010-4346, Low)

* A logic error in the orinoco_ioctl_set_auth() function in the Linux
kernel's ORiNOCO wireless extensions support implementation could render
TKIP countermeasures ineffective when it is enabled, as it enabled the card
instead of shutting it down. (CVE-2010-4648, Low)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel's ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

* An information leak was found in the Linux kernel's task_show_regs()
implementation. On IBM S/390 systems, a local, unprivileged user could use
this flaw to read /proc/[PID]/status files, allowing them to discover
the CPU register values of processes. (CVE-2011-0710, Low)

Red Hat would like to thank Jens Kuehnel for reporting CVE-2011-0695; Kees
Cook for reporting CVE-2010-4656 and CVE-2010-4655; Dan Rosenberg for
reporting CVE-2010-3296; and Tavis Ormandy for reporting CVE-2010-4346.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-07" />
        <updated date="2011-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3296.html">CVE-2010-3296</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4346.html">CVE-2010-4346</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4526.html">CVE-2010-4526</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4648.html">CVE-2010-4648</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4655.html">CVE-2010-4655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4656.html">CVE-2010-4656</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0521.html">CVE-2011-0521</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0695.html">CVE-2011-0695</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0710.html">CVE-2011-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0716.html">CVE-2011-0716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1478.html">CVE-2011-1478</cve>
                <bugzilla href="http://bugzilla.redhat.com/633149" id="633149">CVE-2010-3296 kernel: drivers/net/cxgb3/cxgb3_main.c reading uninitialized stack memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653648" id="653648">CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662189" id="662189">CVE-2010-4346 kernel: install_special_mapping skips security_file_mmap check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664914" id="664914">CVE-2010-4526 kernel: sctp: a race between ICMP protocol unreachable and connect()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667907" id="667907">CVE-2010-4648 kernel: orinoco: fix TKIP countermeasure behaviour</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672398" id="672398">CVE-2011-0521 kernel: av7110 negative array offset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672420" id="672420">CVE-2010-4656 kernel: iowarrior usb device heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672428" id="672428">CVE-2010-4655 kernel: heap contents leak for CAP_NET_ADMIN via ethtool ioctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677850" id="677850">CVE-2011-0710 kernel: s390 task_show_regs infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678169" id="678169">CVE-2011-0716 kernel: deficiency in processing igmp host membership reports in br_multicast</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678558" id="678558">virtio_console driver never returns from selecting for write when the queue is full [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678559" id="678559">Disallow 0-sized writes to virtio ports to go through to host (leading to VM crash) [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678562" id="678562">writing to a virtio serial port while no one is listening on the host side hangs the guest [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680080" id="680080">Start multi RHEL5.5 64 bit guests triggers rtl8169_interrupt hang [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683442" id="683442">backport set_iounmap_nonlazy() to speedup reading of /proc/vmcore [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683445" id="683445">Backport upstream cacheing fix for optimizing reads from /proc/vmcore [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683781" id="683781">kvm: guest stale memory after migration [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683783" id="683783">guest kernel panic when boot with nmi_watchdog=1 [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683822" id="683822">kernel: restrict unprivileged access to kernel syslog [rhel-6.1] [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684267" id="684267">kernel: missing CONFIG_STRICT_DEVMEM=y in S390x [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684268" id="684268">virtio_net: missing schedule on oom [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691270" id="691270">CVE-2011-1478 kernel: gro: reset dev and skb_iff on skb reuse</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421021" comment="kernel-firmware is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421007" comment="kernel-headers is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421005" comment="kernel is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421023" comment="kernel-doc is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421011" comment="kernel-devel is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421025" comment="perf is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421015" comment="kernel-debug is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421017" comment="kernel-kdump is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421013" comment="kernel-debug-devel is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421019" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110421009" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.24.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110422" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0422: postfix security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0422-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0422.html" />
          <reference source="CVE" ref_id="CVE-2008-2937" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2937.html" />
          <reference source="CVE" ref_id="CVE-2011-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0411.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

It was discovered that Postfix did not flush the received SMTP commands
buffer after switching to TLS encryption for an SMTP session. A
man-in-the-middle attacker could use this flaw to inject SMTP commands into
a victim's session during the plain text phase. This would lead to those
commands being processed by Postfix after TLS encryption is enabled,
possibly allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-0411)

It was discovered that Postfix did not properly check the permissions of
users' mailbox files. A local attacker able to create files in the mail
spool directory could use this flaw to create mailbox files for other local
users, and be able to read mail delivered to those users. (CVE-2008-2937)

Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411, and
Sebastian Krahmer of the SuSE Security Team for reporting CVE-2008-2937.
The CERT/CC acknowledges Wietse Venema as the original reporter of
CVE-2011-0411.

Users of Postfix are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the postfix service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-06" />
        <updated date="2011-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2937.html">CVE-2008-2937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0411.html">CVE-2011-0411</cve>
                <bugzilla href="http://bugzilla.redhat.com/456347" id="456347">CVE-2008-2937 postfix improper mailbox permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674814" id="674814">CVE-2011-0411 postfix: SMTP commands injection during plaintext to TLS session switch</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110422004" comment="postfix-pflogsumm is earlier than 2:2.3.3-2.2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422005" comment="postfix-pflogsumm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110422002" comment="postfix is earlier than 2:2.3.3-2.2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422003" comment="postfix is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110422009" comment="postfix-pflogsumm is earlier than 2:2.2.10-1.4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422010" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110422007" comment="postfix is earlier than 2:2.2.10-1.4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422008" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110423" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0423: postfix security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0423.html" />
          <reference source="CVE" ref_id="CVE-2011-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0411.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

It was discovered that Postfix did not flush the received SMTP commands
buffer after switching to TLS encryption for an SMTP session. A
man-in-the-middle attacker could use this flaw to inject SMTP commands into
a victim's session during the plain text phase. This would lead to those
commands being processed by Postfix after TLS encryption is enabled,
possibly allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-0411)

Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411. The
CERT/CC acknowledges Wietse Venema as the original reporter.

Users of Postfix are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the postfix service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-06" />
        <updated date="2011-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0411.html">CVE-2011-0411</cve>
                <bugzilla href="http://bugzilla.redhat.com/674814" id="674814">CVE-2011-0411 postfix: SMTP commands injection during plaintext to TLS session switch</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110423007" comment="postfix-perl-scripts is earlier than 2:2.6.6-2.1.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110423008" comment="postfix-perl-scripts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110423005" comment="postfix is earlier than 2:2.6.6-2.1.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110423006" comment="postfix is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110426" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0426: spice-xpi security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0426-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0426.html" />
          <reference source="CVE" ref_id="CVE-2011-0012" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0012.html" />
          <reference source="CVE" ref_id="CVE-2011-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1179.html" />
    
    <description>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

An uninitialized pointer use flaw was found in the SPICE Firefox plug-in.
If a user were tricked into visiting a malicious web page with Firefox
while the SPICE plug-in was enabled, it could cause Firefox to crash or,
possibly, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-1179)

It was found that the SPICE Firefox plug-in used a predictable name for one
of its log files. A local attacker could use this flaw to conduct a
symbolic link attack, allowing them to overwrite arbitrary files accessible
to the user running Firefox. (CVE-2011-0012)

Users of spice-xpi should upgrade to this updated package, which contains
backported patches to correct these issues. After installing the update,
Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-07" />
        <updated date="2011-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0012.html">CVE-2011-0012</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1179.html">CVE-2011-1179</cve>
                <bugzilla href="http://bugzilla.redhat.com/639869" id="639869">CVE-2011-0012 spice-xpi: symlink attack on usbrdrctl log file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689931" id="689931">CVE-2011-1179 spice-xpi: unitialized pointer writes possible when getting plugin properties</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110426005" comment="spice-xpi is earlier than 0:2.4-1.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110426006" comment="spice-xpi is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110427" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0427: spice-xpi security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0427.html" />
          <reference source="CVE" ref_id="CVE-2011-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1179.html" />
    
    <description>The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

An uninitialized pointer use flaw was found in the SPICE Firefox plug-in.
If a user were tricked into visiting a malicious web page with Firefox
while the SPICE plug-in was enabled, it could cause Firefox to crash or,
possibly, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-1179)

Users of spice-xpi should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing the update,
Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-07" />
        <updated date="2011-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1179.html">CVE-2011-1179</cve>
                <bugzilla href="http://bugzilla.redhat.com/689931" id="689931">CVE-2011-1179 spice-xpi: unitialized pointer writes possible when getting plugin properties</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110427002" comment="spice-xpi is earlier than 0:2.2-2.3.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110427003" comment="spice-xpi is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110428" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0428: dhcp security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0428.html" />
          <reference source="CVE" ref_id="CVE-2011-0997" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0997.html" />
    
    <description>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

It was discovered that the DHCP client daemon, dhclient, did not
sufficiently sanitize certain options provided in DHCP server replies, such
as the client hostname. A malicious DHCP server could send such an option
with a specially-crafted value to a DHCP client. If this option's value was
saved on the client system, and then later insecurely evaluated by a
process that assumes the option is trusted, it could lead to arbitrary code
execution with the privileges of that process. (CVE-2011-0997)

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for
reporting this issue.

All dhclient users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-08" />
        <updated date="2011-04-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0997.html">CVE-2011-0997</cve>
                <bugzilla href="http://bugzilla.redhat.com/689832" id="689832">CVE-2011-0997 dhclient: insufficient sanitization of certain DHCP response values</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428008" comment="libdhcp4client-devel is earlier than 12:3.0.5-23.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428009" comment="libdhcp4client-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428010" comment="dhclient is earlier than 12:3.0.5-23.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428011" comment="dhclient is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428006" comment="dhcp-devel is earlier than 12:3.0.5-23.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428007" comment="dhcp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428002" comment="dhcp is earlier than 12:3.0.5-23.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428003" comment="dhcp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428004" comment="libdhcp4client is earlier than 12:3.0.5-23.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428005" comment="libdhcp4client is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428020" comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256010" comment="dhclient is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428018" comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256008" comment="dhcp-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428016" comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256006" comment="dhcp is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428027" comment="dhclient is earlier than 7:3.0.1-67.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428028" comment="dhclient is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428025" comment="dhcp-devel is earlier than 7:3.0.1-67.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428026" comment="dhcp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110428023" comment="dhcp is earlier than 7:3.0.1-67.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428024" comment="dhcp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110429" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0429: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0429.html" />
          <reference source="CVE" ref_id="CVE-2010-4346" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4346.html" />
          <reference source="CVE" ref_id="CVE-2011-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0521.html" />
          <reference source="CVE" ref_id="CVE-2011-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0710.html" />
          <reference source="CVE" ref_id="CVE-2011-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1010.html" />
          <reference source="CVE" ref_id="CVE-2011-1090" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1090.html" />
          <reference source="CVE" ref_id="CVE-2011-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1478.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel's av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* An inconsistency was found in the interaction between the Linux kernel's
method for allocating NFSv4 (Network File System version 4) ACL data and
the method by which it was freed. This inconsistency led to a kernel panic
which could be triggered by a local, unprivileged user with files owned by
said user on an NFSv4 share. (CVE-2011-1090, Moderate)

* A NULL pointer dereference flaw was found in the Generic Receive Offload
(GRO) functionality in the Linux kernel's networking implementation. If
both GRO and promiscuous mode were enabled on an interface in a virtual LAN
(VLAN), it could result in a denial of service when a malformed VLAN frame
is received on that interface. (CVE-2011-1478, Moderate)

* A missing security check in the Linux kernel's implementation of the
install_special_mapping() function could allow a local, unprivileged user
to bypass the mmap_min_addr protection mechanism. (CVE-2010-4346, Low)

* An information leak was found in the Linux kernel's task_show_regs()
implementation. On IBM S/390 systems, a local, unprivileged user could use
this flaw to read /proc/[PID]/status files, allowing them to discover the
CPU register values of processes. (CVE-2011-0710, Low)

* A missing validation check was found in the Linux kernel's
mac_partition() implementation, used for supporting file systems created
on Mac OS operating systems. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partitions. (CVE-2011-1010, Low)

Red Hat would like to thank Ryan Sweat for reporting CVE-2011-1478; Tavis
Ormandy for reporting CVE-2010-4346; and Timo Warns for reporting
CVE-2011-1010.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-12" />
        <updated date="2011-04-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4346.html">CVE-2010-4346</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0521.html">CVE-2011-0521</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0710.html">CVE-2011-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1010.html">CVE-2011-1010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1090.html">CVE-2011-1090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1478.html">CVE-2011-1478</cve>
                <bugzilla href="http://bugzilla.redhat.com/662189" id="662189">CVE-2010-4346 kernel: install_special_mapping skips security_file_mmap check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672398" id="672398">CVE-2011-0521 kernel: av7110 negative array offset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675664" id="675664">Kernel panic when restart network on vlan with bonding [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675909" id="675909">GFS2: Blocks not marked free on delete [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677173" id="677173">mpctl module doesn't release fasync_struct at file close [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677850" id="677850">CVE-2011-0710 kernel: s390 task_show_regs infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679282" id="679282">CVE-2011-1010 kernel: fs/partitions: Validate map_count in Mac partition tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680043" id="680043">[usb-audio] unable to set capture mixer levels [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680350" id="680350">WARNING: APIC timer calibration may be wrong [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681795" id="681795">[NetApp 5.6 Bug] Erroneous TPG ID check in SCSI ALUA Handler [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682641" id="682641">CVE-2011-1090 kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682673" id="682673">system fails to boot do to x86-64 kernel corrupting bios memory area [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683443" id="683443">kernel panic in pg_init_done - pgpath already deleted [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684128" id="684128">HP_GETHOSTINFO ioctl always causes mpt controller reset [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691270" id="691270">CVE-2011-1478 kernel: gro: reset dev and skb_iff on skb reuse</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429004" comment="kernel-headers is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429002" comment="kernel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429024" comment="kernel-doc is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429022" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429012" comment="kernel-devel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429010" comment="kernel-debug is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429018" comment="kernel-kdump is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429014" comment="kernel-xen-devel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429006" comment="kernel-debug-devel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429020" comment="kernel-PAE is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429016" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110429008" comment="kernel-xen is earlier than 0:2.6.18-238.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110432" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0432: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0432-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0432.html" />
          <reference source="CVE" ref_id="CVE-2011-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0465.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the X.Org X server resource database utility, xrdb.
Certain variables were not properly sanitized during the launch of a user's
graphical session, which could possibly allow a remote attacker to execute
arbitrary code with root privileges, if they were able to make the display
manager execute xrdb with a specially-crafted X client hostname. For
example, by configuring the hostname on the target system via a crafted
DHCP reply, or by using the X Display Manager Control Protocol (XDMCP) to
connect to that system from a host that has a special DNS name.
(CVE-2011-0465)

Red Hat would like to thank Matthieu Herrb for reporting this issue.
Upstream acknowledges Sebastian Krahmer of the SuSE Security Team as the
original reporter.

Users of xorg-x11 should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-11" />
        <updated date="2011-04-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0465.html">CVE-2011-0465</cve>
                <bugzilla href="http://bugzilla.redhat.com/680196" id="680196">CVE-2011-0465 xorg: xrdb code execution via crafted X client hostname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432036" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432037" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432032" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432033" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432026" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432027" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432022" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432023" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432020" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432021" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432016" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432017" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432012" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432024" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432025" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432010" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432011" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432034" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432035" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432018" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432019" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432006" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432007" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432004" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432005" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432030" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432031" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432028" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432029" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110432008" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.67" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432009" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110433" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0433: xorg-x11-server-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0433-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0433.html" />
          <reference source="CVE" ref_id="CVE-2011-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0465.html" />
    
    <description>The xorg-x11-server-utils package contains a collection of utilities used
to modify and query the runtime configuration of the X.Org server. X.Org is
an open source implementation of the X Window System.

A flaw was found in the X.Org X server resource database utility, xrdb.
Certain variables were not properly sanitized during the launch of a user's
graphical session, which could possibly allow a remote attacker to execute
arbitrary code with root privileges, if they were able to make the display
manager execute xrdb with a specially-crafted X client hostname. For
example, by configuring the hostname on the target system via a crafted
DHCP reply, or by using the X Display Manager Control Protocol (XDMCP) to
connect to that system from a host that has a special DNS name.
(CVE-2011-0465)

Red Hat would like to thank Matthieu Herrb for reporting this issue.
Upstream acknowledges Sebastian Krahmer of the SuSE Security Team as the
original reporter.

Users of xorg-x11-server-utils should upgrade to this updated package,
which contains a backported patch to resolve this issue. All running X.Org
server instances must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-11" />
        <updated date="2011-04-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0465.html">CVE-2011-0465</cve>
                <bugzilla href="http://bugzilla.redhat.com/680196" id="680196">CVE-2011-0465 xorg: xrdb code execution via crafted X client hostname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110433002" comment="xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110433003" comment="xorg-x11-server-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110433008" comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110433009" comment="xorg-x11-server-utils is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110436" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0436: avahi security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0436.html" />
          <reference source="CVE" ref_id="CVE-2011-1002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1002.html" />
    
    <description>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zero Configuration Networking. It facilitates service
discovery on a local network. Avahi and Avahi-aware applications allow you
to plug your computer into a network and, with no configuration, view other
people to chat with, view printers to print to, and find shared files on
other computers.

A flaw was found in the way the Avahi daemon (avahi-daemon) processed
Multicast DNS (mDNS) packets with an empty payload. An attacker on the
local network could use this flaw to cause avahi-daemon on a target system
to enter an infinite loop via an empty mDNS UDP packet. (CVE-2011-1002)

All users are advised to upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update,
avahi-daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-12" />
        <updated date="2011-04-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1002.html">CVE-2011-1002</cve>
                <bugzilla href="http://bugzilla.redhat.com/667187" id="667187">CVE-2011-1002 avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436018" comment="avahi-compat-howl is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436019" comment="avahi-compat-howl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436010" comment="avahi-glib-devel is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436011" comment="avahi-glib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436002" comment="avahi is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436003" comment="avahi is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436004" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436005" comment="avahi-compat-howl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436016" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436017" comment="avahi-compat-libdns_sd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436006" comment="avahi-glib is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436007" comment="avahi-glib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436022" comment="avahi-qt3 is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436023" comment="avahi-qt3 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436020" comment="avahi-tools is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436021" comment="avahi-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436012" comment="avahi-qt3-devel is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436013" comment="avahi-qt3-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436008" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436009" comment="avahi-compat-libdns_sd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110436014" comment="avahi-devel is earlier than 0:0.6.16-10.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110436015" comment="avahi-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110447" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0447: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0447-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0447.html" />
          <reference source="CVE" ref_id="CVE-2011-0285" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0285.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

An invalid free flaw was found in the password-changing capability of the
MIT Kerberos administration daemon, kadmind. A remote, unauthenticated
attacker could use this flaw to cause kadmind to abort via a
specially-crafted request. (CVE-2011-0285)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the kadmind daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-14" />
        <updated date="2011-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0285.html">CVE-2011-0285</cve>
                <bugzilla href="http://bugzilla.redhat.com/696334" id="696334">CVE-2011-0285 krb5: kadmind invalid pointer free() (MITKRB5-SA-004)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447013" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200008" comment="krb5-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447009" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200016" comment="krb5-pkinit-openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447011" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200014" comment="krb5-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447007" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200018" comment="krb5-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447015" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200012" comment="krb5-server-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447005" comment="krb5 is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200006" comment="krb5 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110447017" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200010" comment="krb5-workstation is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110451" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0451: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0451.html" />
          <reference source="CVE" ref_id="CVE-2011-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0611.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed on the Adobe security page APSB11-07, listed in
the References section. Specially-crafted SWF content could cause
flash-plugin to crash or, potentially, execute arbitrary code.
(CVE-2011-0611)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.2.159.1.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-18" />
        <updated date="2011-04-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0611.html">CVE-2011-0611</cve>
                <bugzilla href="http://bugzilla.redhat.com/695546" id="695546">CVE-2011-0611 flash-plugin: crash and potential arbitrary code execution (APSB11-07)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110451002" comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110451008" comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110452" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0452: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0452-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0452.html" />
          <reference source="CVE" ref_id="CVE-2009-5022" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5022.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF image files that were compressed with the JPEG compression
algorithm. An attacker could use this flaw to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2009-5022)

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications linked
against libtiff must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-18" />
        <updated date="2011-04-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-5022.html">CVE-2009-5022</cve>
                <bugzilla href="http://bugzilla.redhat.com/695885" id="695885">CVE-2009-5022 libtiff ojpeg buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110452009" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318013" comment="libtiff-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110452005" comment="libtiff is earlier than 0:3.9.4-1.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318011" comment="libtiff is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110452007" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110318015" comment="libtiff-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110455" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0455: polkit security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0455.html" />
          <reference source="CVE" ref_id="CVE-2011-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1485.html" />
    
    <description>PolicyKit is a toolkit for defining and handling authorizations.

A race condition flaw was found in the PolicyKit pkexec utility and polkitd
daemon. A local user could use this flaw to appear as a privileged user to
pkexec, allowing them to execute arbitrary commands as root by running
those commands with pkexec. (CVE-2011-1485)

Red Hat would like to thank Neel Mehta of Google for reporting this issue.

All polkit users should upgrade to these updated packages, which contain
backported patches to correct this issue. The system must be rebooted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-19" />
        <updated date="2011-04-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1485.html">CVE-2011-1485</cve>
                <bugzilla href="http://bugzilla.redhat.com/692922" id="692922">CVE-2011-1485 polkitd/pkexec vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110455007" comment="polkit-devel is earlier than 0:0.96-2.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110455008" comment="polkit-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110455005" comment="polkit is earlier than 0:0.96-2.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110455006" comment="polkit is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110455011" comment="polkit-desktop-policy is earlier than 0:0.96-2.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110455012" comment="polkit-desktop-policy is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110455009" comment="polkit-docs is earlier than 0:0.96-2.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110455010" comment="polkit-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110464" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0464: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0464-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0464.html" />
          <reference source="CVE" ref_id="CVE-2011-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1094.html" />
          <reference source="CVE" ref_id="CVE-2011-1168" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1168.html" />
    
    <description>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A cross-site scripting (XSS) flaw was found in the way KHTML, the HTML
layout engine used by KDE applications such as the Konqueror web browser,
displayed certain error pages. A remote attacker could use this flaw to
perform a cross-site scripting attack against victims by tricking them into
visiting a specially-crafted URL. (CVE-2011-1168)

A flaw was found in the way kdelibs checked the user specified hostname
against the name in the server's SSL certificate. A man-in-the-middle
attacker could use this flaw to trick an application using kdelibs into
mistakenly accepting a certificate as if it was valid for the host, if that
certificate was issued for an IP address to which the user specified
hostname was resolved to. (CVE-2011-1094)

Note: As part of the fix for CVE-2011-1094, this update also introduces
stricter handling for wildcards used in servers' SSL certificates.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-21" />
        <updated date="2011-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1094.html">CVE-2011-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1168.html">CVE-2011-1168</cve>
                <bugzilla href="http://bugzilla.redhat.com/632114" id="632114">CVE-2011-1094 kdelibs: SSL certificate for IP address accepted as valid for hosts that resolve to the IP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695398" id="695398">CVE-2011-1168 kdelibs: partially universal XSS in Konqueror error pages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110464007" comment="kdelibs-common is earlier than 6:4.3.4-11.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110464008" comment="kdelibs-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110464009" comment="kdelibs-apidocs is earlier than 6:4.3.4-11.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110464010" comment="kdelibs-apidocs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110464005" comment="kdelibs is earlier than 6:4.3.4-11.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110464006" comment="kdelibs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110464011" comment="kdelibs-devel is earlier than 6:4.3.4-11.el6_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110464012" comment="kdelibs-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110465" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0465: kdenetwork security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0465.html" />
          <reference source="CVE" ref_id="CVE-2011-1586" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1586.html" />
    
    <description>The kdenetwork packages contain networking applications for the K Desktop
Environment (KDE).

A directory traversal flaw was found in the way KGet, a download manager,
handled the "file" element in Metalink files. An attacker could use this
flaw to create a specially-crafted Metalink file that, when opened, would
cause KGet to overwrite arbitrary files accessible to the user running
KGet. (CVE-2011-1586)

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch to resolve this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-21" />
        <updated date="2011-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1586.html">CVE-2011-1586</cve>
                <bugzilla href="http://bugzilla.redhat.com/697042" id="697042">CVE-2011-1586 kdenetwork: incomplete fix for CVE-2010-1000</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110465005" comment="kdenetwork is earlier than 7:4.3.4-11.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110465006" comment="kdenetwork is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110465007" comment="kdenetwork-libs is earlier than 7:4.3.4-11.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110465008" comment="kdenetwork-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110465009" comment="kdenetwork-devel is earlier than 7:4.3.4-11.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110465010" comment="kdenetwork-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110471" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0471: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0471-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0471.html" />
          <reference source="CVE" ref_id="CVE-2011-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0065.html" />
          <reference source="CVE" ref_id="CVE-2011-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0066.html" />
          <reference source="CVE" ref_id="CVE-2011-0067" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0067.html" />
          <reference source="CVE" ref_id="CVE-2011-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0069.html" />
          <reference source="CVE" ref_id="CVE-2011-0070" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0070.html" />
          <reference source="CVE" ref_id="CVE-2011-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0071.html" />
          <reference source="CVE" ref_id="CVE-2011-0072" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0072.html" />
          <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html" />
          <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html" />
          <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html" />
          <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html" />
          <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html" />
          <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html" />
          <reference source="CVE" ref_id="CVE-2011-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0081.html" />
          <reference source="CVE" ref_id="CVE-2011-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1202.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could possibly lead to arbitrary code
execution with the privileges of the user running Firefox. (CVE-2011-0080,
CVE-2011-0081)

An arbitrary memory write flaw was found in the way Firefox handled
out-of-memory conditions. If all memory was consumed when a user visited a
malicious web page, it could possibly lead to arbitrary code execution
with the privileges of the user running Firefox. (CVE-2011-0078)

An integer overflow flaw was found in the way Firefox handled the HTML
frameset tag. A web page with a frameset tag containing large values for
the "rows" and "cols" attributes could trigger this flaw, possibly leading
to arbitrary code execution with the privileges of the user running
Firefox. (CVE-2011-0077)

A flaw was found in the way Firefox handled the HTML iframe tag. A web page
with an iframe tag containing a specially-crafted source address could
trigger this flaw, possibly leading to arbitrary code execution with the
privileges of the user running Firefox. (CVE-2011-0075)

A flaw was found in the way Firefox displayed multiple marquee elements. A
malformed HTML document could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0074)

A flaw was found in the way Firefox handled the nsTreeSelection element.
Malformed content could cause Firefox to execute arbitrary code with the
privileges of the user running Firefox. (CVE-2011-0073)

A use-after-free flaw was found in the way Firefox appended frame and
iframe elements to a DOM tree when the NoScript add-on was enabled.
Malicious HTML content could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0072)

A directory traversal flaw was found in the Firefox resource:// protocol
handler. Malicious content could cause Firefox to access arbitrary files
accessible to the user running Firefox. (CVE-2011-0071)

A double free flaw was found in the way Firefox handled
"application/http-index-format" documents. A malformed HTTP response could
cause Firefox to execute arbitrary code with the privileges of the user
running Firefox. (CVE-2011-0070)

A flaw was found in the way Firefox handled certain JavaScript cross-domain
requests. If malicious content generated a large number of cross-domain
JavaScript requests, it could cause Firefox to execute arbitrary code with
the privileges of the user running Firefox. (CVE-2011-0069)

A flaw was found in the way Firefox displayed the autocomplete pop-up.
Malicious content could use this flaw to steal form history information.
(CVE-2011-0067)

Two use-after-free flaws were found in the Firefox mObserverList and
mChannel objects. Malicious content could use these flaws to execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2011-0066, CVE-2011-0065)

A flaw was found in the Firefox XSLT generate-id() function. This function
returned the memory address of an object in memory, which could possibly be
used by attackers to bypass address randomization protections.
(CVE-2011-1202)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.17. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.17, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-28" />
        <updated date="2011-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0065.html">CVE-2011-0065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0066.html">CVE-2011-0066</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0067.html">CVE-2011-0067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0069.html">CVE-2011-0069</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0070.html">CVE-2011-0070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0071.html">CVE-2011-0071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0072.html">CVE-2011-0072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0073.html">CVE-2011-0073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0074.html">CVE-2011-0074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0075.html">CVE-2011-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0077.html">CVE-2011-0077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0078.html">CVE-2011-0078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0080.html">CVE-2011-0080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0081.html">CVE-2011-0081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1202.html">CVE-2011-1202</cve>
                <bugzilla href="http://bugzilla.redhat.com/684386" id="684386">CVE-2011-1202 libxslt: Heap address leak in XLST</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700603" id="700603">CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700613" id="700613">CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700615" id="700615">CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700617" id="700617">CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700619" id="700619">CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700622" id="700622">CVE-2011-0072 Mozilla use after free flaw (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700635" id="700635">CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700640" id="700640">CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700642" id="700642">CVE-2011-0069 Mozilla javascript crash (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700644" id="700644">CVE-2011-0067 Mozilla untrusted events can trigger autocomplete popup (MFSA 2011-14)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700657" id="700657">CVE-2011-0066 Mozilla mObserverList use after free (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700658" id="700658">CVE-2011-0065 Mozilla mChannel use after free (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700676" id="700676">CVE-2011-0081 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700677" id="700677">CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471002" comment="firefox is earlier than 0:3.6.17-1.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471004" comment="xulrunner is earlier than 0:1.9.2.17-3.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471006" comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471012" comment="firefox is earlier than 0:3.6.17-1.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471014" comment="xulrunner is earlier than 0:1.9.2.17-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110471016" comment="xulrunner-devel is earlier than 0:1.9.2.17-4.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110471019" comment="firefox is earlier than 0:3.6.17-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110472" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0472: nss security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0472.html" />
    
    <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

This erratum blacklists a small number of HTTPS certificates by adding
them, flagged as untrusted, to the NSS Builtin Object Token (the
libnssckbi.so library) certificate store. (BZ#689430)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not blacklist the certificates for applications that use the
NSS library, but do not use the NSS Builtin Object Token (such as curl).

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-28" />
        <updated date="2011-04-28" />
                <bugzilla href="http://bugzilla.redhat.com/689430" id="689430">Compromised certificates</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472002" comment="nss is earlier than 0:3.12.8-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472003" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472008" comment="nss-tools is earlier than 0:3.12.8-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472009" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472006" comment="nss-pkcs11-devel is earlier than 0:3.12.8-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472007" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472004" comment="nss-devel is earlier than 0:3.12.8-4.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472005" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472020" comment="nss-sysinit is earlier than 0:3.12.8-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472021" comment="nss-sysinit is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472014" comment="nss is earlier than 0:3.12.8-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472015" comment="nss is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472018" comment="nss-tools is earlier than 0:3.12.8-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472019" comment="nss-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472022" comment="nss-devel is earlier than 0:3.12.8-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472023" comment="nss-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472016" comment="nss-pkcs11-devel is earlier than 0:3.12.8-3.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472017" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472025" comment="nss is earlier than 0:3.12.8-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472026" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472029" comment="nss-tools is earlier than 0:3.12.8-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472030" comment="nss-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110472027" comment="nss-devel is earlier than 0:3.12.8-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472028" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110473" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0473: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0473-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0473.html" />
          <reference source="CVE" ref_id="CVE-2011-0072" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0072.html" />
          <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html" />
          <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html" />
          <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html" />
          <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html" />
          <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html" />
          <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could possibly lead to arbitrary code
execution with the privileges of the user running SeaMonkey.
(CVE-2011-0080)

An arbitrary memory write flaw was found in the way SeaMonkey handled
out-of-memory conditions. If all memory was consumed when a user visited a
malicious web page, it could possibly lead to arbitrary code execution
with the privileges of the user running SeaMonkey. (CVE-2011-0078)

An integer overflow flaw was found in the way SeaMonkey handled the HTML
frameset tag. A web page with a frameset tag containing large values for
the "rows" and "cols" attributes could trigger this flaw, possibly leading
to arbitrary code execution with the privileges of the user running
SeaMonkey. (CVE-2011-0077)

A flaw was found in the way SeaMonkey handled the HTML iframe tag. A web
page with an iframe tag containing a specially-crafted source address could
trigger this flaw, possibly leading to arbitrary code execution with the
privileges of the user running SeaMonkey. (CVE-2011-0075)

A flaw was found in the way SeaMonkey displayed multiple marquee elements.
A malformed HTML document could cause SeaMonkey to execute arbitrary code
with the privileges of the user running SeaMonkey. (CVE-2011-0074)

A flaw was found in the way SeaMonkey handled the nsTreeSelection element.
Malformed content could cause SeaMonkey to execute arbitrary code with the
privileges of the user running SeaMonkey. (CVE-2011-0073)

A use-after-free flaw was found in the way SeaMonkey appended frame and
iframe elements to a DOM tree when the NoScript add-on was enabled.
Malicious HTML content could cause SeaMonkey to execute arbitrary code with
the privileges of the user running SeaMonkey. (CVE-2011-0072)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-28" />
        <updated date="2011-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0072.html">CVE-2011-0072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0073.html">CVE-2011-0073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0074.html">CVE-2011-0074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0075.html">CVE-2011-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0077.html">CVE-2011-0077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0078.html">CVE-2011-0078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0080.html">CVE-2011-0080</cve>
                <bugzilla href="http://bugzilla.redhat.com/700603" id="700603">CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700613" id="700613">CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700615" id="700615">CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700617" id="700617">CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700619" id="700619">CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700622" id="700622">CVE-2011-0072 Mozilla use after free flaw (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700677" id="700677">CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473008" comment="seamonkey-mail is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473002" comment="seamonkey is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473010" comment="seamonkey-devel is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473006" comment="seamonkey-chat is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110473004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-70.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110474" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0474: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0474-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0474.html" />
          <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html" />
          <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html" />
          <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html" />
          <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html" />
          <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html" />
          <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could possibly lead to
arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-0080)

An arbitrary memory write flaw was found in the way Thunderbird handled
out-of-memory conditions. If all memory was consumed when a user viewed a
malicious HTML mail message, it could possibly lead to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0078)

An integer overflow flaw was found in the way Thunderbird handled the HTML
frameset tag. An HTML mail message with a frameset tag containing large
values for the "rows" and "cols" attributes could trigger this flaw,
possibly leading to arbitrary code execution with the privileges of the
user running Thunderbird. (CVE-2011-0077)

A flaw was found in the way Thunderbird handled the HTML iframe tag. An
HTML mail message with an iframe tag containing a specially-crafted source
address could trigger this flaw, possibly leading to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0075)

A flaw was found in the way Thunderbird displayed multiple marquee
elements. A malformed HTML mail message could cause Thunderbird to execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0074)

A flaw was found in the way Thunderbird handled the nsTreeSelection
element. Malformed content could cause Thunderbird to execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0073)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-28" />
        <updated date="2011-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0073.html">CVE-2011-0073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0074.html">CVE-2011-0074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0075.html">CVE-2011-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0077.html">CVE-2011-0077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0078.html">CVE-2011-0078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0080.html">CVE-2011-0080</cve>
                <bugzilla href="http://bugzilla.redhat.com/700603" id="700603">CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700613" id="700613">CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700615" id="700615">CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700617" id="700617">CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700619" id="700619">CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700677" id="700677">CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110474002" comment="thunderbird is earlier than 0:2.0.0.24-17.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110474005" comment="thunderbird is earlier than 0:1.5.0.12-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110475" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0475: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0475-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0475.html" />
          <reference source="CVE" ref_id="CVE-2011-0070" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0070.html" />
          <reference source="CVE" ref_id="CVE-2011-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0071.html" />
          <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html" />
          <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html" />
          <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html" />
          <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html" />
          <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html" />
          <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html" />
          <reference source="CVE" ref_id="CVE-2011-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0081.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could possibly lead to
arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-0080, CVE-2011-0081)

An arbitrary memory write flaw was found in the way Thunderbird handled
out-of-memory conditions. If all memory was consumed when a user viewed a
malicious HTML mail message, it could possibly lead to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0078)

An integer overflow flaw was found in the way Thunderbird handled the HTML
frameset tag. An HTML mail message with a frameset tag containing large
values for the "rows" and "cols" attributes could trigger this flaw,
possibly leading to arbitrary code execution with the privileges of the
user running Thunderbird. (CVE-2011-0077)

A flaw was found in the way Thunderbird handled the HTML iframe tag. An
HTML mail message with an iframe tag containing a specially-crafted source
address could trigger this flaw, possibly leading to arbitrary code
execution with the privileges of the user running Thunderbird.
(CVE-2011-0075)

A flaw was found in the way Thunderbird displayed multiple marquee
elements. A malformed HTML mail message could cause Thunderbird to execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0074)

A flaw was found in the way Thunderbird handled the nsTreeSelection
element. Malformed content could cause Thunderbird to execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0073)

A directory traversal flaw was found in the Thunderbird resource://
protocol handler. Malicious content could cause Thunderbird to access
arbitrary files accessible to the user running Thunderbird. (CVE-2011-0071)

A double free flaw was found in the way Thunderbird handled
"application/http-index-format" documents. A malformed HTTP response could
cause Thunderbird to execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2011-0070)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-04-28" />
        <updated date="2011-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0070.html">CVE-2011-0070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0071.html">CVE-2011-0071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0073.html">CVE-2011-0073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0074.html">CVE-2011-0074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0075.html">CVE-2011-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0077.html">CVE-2011-0077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0078.html">CVE-2011-0078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0080.html">CVE-2011-0080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0081.html">CVE-2011-0081</cve>
                <bugzilla href="http://bugzilla.redhat.com/700603" id="700603">CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700613" id="700613">CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700615" id="700615">CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700617" id="700617">CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700619" id="700619">CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700635" id="700635">CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700640" id="700640">CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700676" id="700676">CVE-2011-0081 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700677" id="700677">CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110475005" comment="thunderbird is earlier than 0:3.1.10-1.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110477" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0477: gstreamer-plugins security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0477-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0477.html" />
          <reference source="CVE" ref_id="CVE-2006-4192" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4192.html" />
          <reference source="CVE" ref_id="CVE-2011-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1574.html" />
    
    <description>The gstreamer-plugins packages contain plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media formats.

An integer overflow flaw, leading to a heap-based buffer overflow, and a
stack-based buffer overflow flaw were found in various ModPlug music file
format library (libmodplug) modules, embedded in GStreamer. An attacker
could create specially-crafted music files that, when played by a victim,
would cause applications using GStreamer to crash or, potentially, execute
arbitrary code. (CVE-2006-4192, CVE-2011-1574)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as Rhythmbox)
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-02" />
        <updated date="2011-05-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4192.html">CVE-2006-4192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1574.html">CVE-2011-1574</cve>
                <bugzilla href="http://bugzilla.redhat.com/497154" id="497154">CVE-2006-4192 libmodplug: Integer overflow when reading samples of AMF files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695420" id="695420">CVE-2011-1574 libmodplug: ReadS3M stack overflow vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110477004" comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110477005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110477002" comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110477003" comment="gstreamer-plugins is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110478" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0478: libvirt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0478.html" />
          <reference source="CVE" ref_id="CVE-2011-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1486.html" />
    
    <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

A flaw was found in the way libvirtd handled error reporting for concurrent
connections. A remote attacker able to establish read-only connections to
libvirtd on a server could use this flaw to crash libvirtd. (CVE-2011-1486)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-02" />
        <updated date="2011-05-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1486.html">CVE-2011-1486</cve>
                <bugzilla href="http://bugzilla.redhat.com/693391" id="693391">CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110478004" comment="libvirt-devel is earlier than 0:0.8.2-15.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391005" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110478002" comment="libvirt is earlier than 0:0.8.2-15.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391003" comment="libvirt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110478006" comment="libvirt-python is earlier than 0:0.8.2-15.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391007" comment="libvirt-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110479" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0479: libvirt security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0479.html" />
          <reference source="CVE" ref_id="CVE-2011-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1486.html" />
    
    <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

A flaw was found in the way libvirtd handled error reporting for concurrent
connections. A remote attacker able to establish read-only connections to
libvirtd on a server could use this flaw to crash libvirtd. (CVE-2011-1486)

This update also fixes the following bug:

* Previously, running qemu under a different UID prevented it from
accessing files with mode 0660 permissions that were owned by a different
user, but by a group that qemu was a member of. (BZ#668692)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
updated packages, libvirtd must be restarted ("service libvirtd restart")
for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-02" />
        <updated date="2011-05-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1486.html">CVE-2011-1486</cve>
                <bugzilla href="http://bugzilla.redhat.com/668692" id="668692">qemu process is spawned with no supplementary groups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/693391" id="693391">CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110479007" comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391015" comment="libvirt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110479005" comment="libvirt is earlier than 0:0.8.1-27.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391013" comment="libvirt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110479011" comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391019" comment="libvirt-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110479009" comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391017" comment="libvirt-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110486" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0486: xmlsec1 security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0486.html" />
          <reference source="CVE" ref_id="CVE-2011-1425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1425.html" />
    
    <description>The XML Security Library is a C library based on libxml2 and OpenSSL that
implements the XML Digital Signature and XML Encryption standards.

A flaw was found in the way xmlsec1 handled XML files that contain an XSLT
transformation specification. A specially-crafted XML file could cause
xmlsec1 to create or overwrite an arbitrary file while performing the
verification of a file's digital signature. (CVE-2011-1425)

Red Hat would like to thank Nicolas Grégoire and Aleksey Sanin for
reporting this issue.

This update also fixes the following bug:

* xmlsec1 previously used an incorrect search path when searching for
crypto plug-in libraries, possibly trying to access such libraries using a
relative path. (BZ#558480, BZ#700467)

Users of xmlsec1 should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the update,
all running applications that use the xmlsec1 library must be restarted for
the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-04" />
        <updated date="2011-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1425.html">CVE-2011-1425</cve>
                <bugzilla href="http://bugzilla.redhat.com/558480" id="558480">xmlsec1: bogus lt_dlopen() search path [rhel-4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692133" id="692133">CVE-2011-1425 xmlsec1: arbitrary file creation when verifying signatures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700467" id="700467">xmlsec1: bogus lt_dlopen() search path [rhel-5]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486006" comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486007" comment="xmlsec1-nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486008" comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486009" comment="xmlsec1-openssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486004" comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486005" comment="xmlsec1-nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486010" comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486011" comment="xmlsec1-gnutls is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486002" comment="xmlsec1 is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486003" comment="xmlsec1 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486016" comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486017" comment="xmlsec1-gnutls-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486014" comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486015" comment="xmlsec1-openssl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486012" comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486013" comment="xmlsec1-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486023" comment="xmlsec1-openssl is earlier than 0:1.2.6-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486024" comment="xmlsec1-openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486019" comment="xmlsec1 is earlier than 0:1.2.6-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486020" comment="xmlsec1 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486025" comment="xmlsec1-openssl-devel is earlier than 0:1.2.6-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486026" comment="xmlsec1-openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110486021" comment="xmlsec1-devel is earlier than 0:1.2.6-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110486022" comment="xmlsec1-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110490" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0490: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0490-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0490.html" />
          <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html" />
          <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html" />
          <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html" />
          <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html" />
          <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html" />
          <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html" />
          <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html" />
          <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html" />
    
    <description>The IBM 1.4.2 SR13-FP9 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2010-4447, CVE-2010-4448,
CVE-2010-4454, CVE-2010-4462, CVE-2010-4465, CVE-2010-4466, CVE-2010-4473,
CVE-2010-4475, CVE-2011-0311)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP9 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-05" />
        <updated date="2011-05-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4447.html">CVE-2010-4447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4448.html">CVE-2010-4448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4454.html">CVE-2010-4454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4462.html">CVE-2010-4462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4465.html">CVE-2010-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4466.html">CVE-2010-4466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4473.html">CVE-2010-4473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4475.html">CVE-2010-4475</cve>
                <bugzilla href="http://bugzilla.redhat.com/675984" id="675984">CVE-2010-4465 OpenJDK Swing timer-based security manager bypass  (6907662)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676023" id="676023">CVE-2010-4448 OpenJDK DNS cache poisoning by untrusted applets (6981922)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677957" id="677957">CVE-2010-4475 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677958" id="677958">CVE-2010-4473 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677961" id="677961">CVE-2010-4466 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677966" id="677966">CVE-2010-4462 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677967" id="677967">CVE-2010-4454 JDK unspecified vulnerability in Sound component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677970" id="677970">CVE-2010-4447 JDK unspecified vulnerability in Deployment component</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/702349" id="702349">CVE-2011-0311 IBM JDK Class file parsing denial-of-service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490008" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490012" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490010" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110490006" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110491" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0491: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0491-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0491.html" />
          <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html" />
          <reference source="CVE" ref_id="CVE-2010-1634" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1634.html" />
          <reference source="CVE" ref_id="CVE-2010-2089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2089.html" />
          <reference source="CVE" ref_id="CVE-2010-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3493.html" />
          <reference source="CVE" ref_id="CVE-2011-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1015.html" />
          <reference source="CVE" ref_id="CVE-2011-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1521.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

Multiple flaws were found in the Python audioop module. Supplying certain
inputs could cause the audioop module to crash or, possibly, execute
arbitrary code. (CVE-2010-1634, CVE-2010-2089)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

A buffer over-read flaw was found in the way the Python Expat parser
handled malformed UTF-8 sequences when processing XML files. A
specially-crafted XML file could cause Python applications using the Python
Expat parser to crash while parsing the file. (CVE-2009-3720)

This update makes Python use the system Expat library rather than its own
internal copy; therefore, users must have the version of Expat shipped with
RHSA-2009:1625 installed, or a later version, to resolve the CVE-2009-3720
issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-05" />
        <updated date="2011-05-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3720.html">CVE-2009-3720</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-1634.html">CVE-2010-1634</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2089.html">CVE-2010-2089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3493.html">CVE-2010-3493</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1015.html">CVE-2011-1015</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1521.html">CVE-2011-1521</cve>
                <bugzilla href="http://bugzilla.redhat.com/531697" id="531697">CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590690" id="590690">CVE-2010-1634 python: audioop: incorrect integer overflow checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598197" id="598197">CVE-2010-2089 Python: Memory corruption in audioop module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632200" id="632200">CVE-2010-3493 Python: SMTP proxy RFC 2821 module DoS (uncaught exception) (Issue #9129)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680094" id="680094">CVE-2011-1015 python (CGIHTTPServer): CGI script source code disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690560" id="690560">CVE-2011-1521 python (urllib, urllib2): Improper management of ftp:// and file:// URL schemes (Issue #11662)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110491004" comment="python-devel is earlier than 0:2.3.4-14.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260011" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110491006" comment="python-docs is earlier than 0:2.3.4-14.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260007" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110491010" comment="tkinter is earlier than 0:2.3.4-14.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260005" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110491002" comment="python is earlier than 0:2.3.4-14.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110491008" comment="python-tools is earlier than 0:2.3.4-14.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110260009" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110492" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0492: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0492-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0492.html" />
          <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html" />
          <reference source="CVE" ref_id="CVE-2010-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3493.html" />
          <reference source="CVE" ref_id="CVE-2011-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1015.html" />
          <reference source="CVE" ref_id="CVE-2011-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1521.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

A buffer over-read flaw was found in the way the Python Expat parser
handled malformed UTF-8 sequences when processing XML files. A
specially-crafted XML file could cause Python applications using the Python
Expat parser to crash while parsing the file. (CVE-2009-3720)

This update makes Python use the system Expat library rather than its own
internal copy; therefore, users must have the version of Expat shipped with
RHSA-2009:1625 installed, or a later version, to resolve the CVE-2009-3720
issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-05" />
        <updated date="2011-05-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3720.html">CVE-2009-3720</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3493.html">CVE-2010-3493</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1015.html">CVE-2011-1015</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1521.html">CVE-2011-1521</cve>
                <bugzilla href="http://bugzilla.redhat.com/531697" id="531697">CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632200" id="632200">CVE-2010-3493 Python: SMTP proxy RFC 2821 module DoS (uncaught exception) (Issue #9129)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680094" id="680094">CVE-2011-1015 python (CGIHTTPServer): CGI script source code disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690560" id="690560">CVE-2011-1521 python (urllib, urllib2): Improper management of ftp:// and file:// URL schemes (Issue #11662)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110492008" comment="python-devel is earlier than 0:2.4.3-44.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027009" comment="python-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110492006" comment="python-libs is earlier than 0:2.4.3-44.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027005" comment="python-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110492004" comment="tkinter is earlier than 0:2.4.3-44.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027011" comment="tkinter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110492002" comment="python is earlier than 0:2.4.3-44.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027003" comment="python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110492010" comment="python-tools is earlier than 0:2.4.3-44.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110027007" comment="python-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110496" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0496: xen security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0496-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0496.html" />
          <reference source="CVE" ref_id="CVE-2011-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1583.html" />
    
    <description>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

It was found that the xc_try_bzip2_decode() and xc_try_lzma_decode() decode
routines did not correctly check for a possible buffer size overflow in the
decoding loop. As well, several integer overflow flaws and missing
error/range checking were found that could lead to an infinite loop. A
privileged guest user could use these flaws to crash the guest or,
possibly, execute arbitrary code in the privileged management domain
(Dom0). (CVE-2011-1583)

All xen users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-09" />
        <updated date="2011-05-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1583.html">CVE-2011-1583</cve>
                <bugzilla href="http://bugzilla.redhat.com/696927" id="696927">CVE-2011-1583 xen: insufficiencies in pv kernel image validation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110496002" comment="xen is earlier than 0:3.0.3-120.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110496006" comment="xen-libs is earlier than 0:3.0.3-120.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496007" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110496004" comment="xen-devel is earlier than 0:3.0.3-120.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496005" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110498" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0498: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0498-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0498.html" />
          <reference source="CVE" ref_id="CVE-2010-4250" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4250.html" />
          <reference source="CVE" ref_id="CVE-2010-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4565.html" />
          <reference source="CVE" ref_id="CVE-2010-4649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4649.html" />
          <reference source="CVE" ref_id="CVE-2011-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0006.html" />
          <reference source="CVE" ref_id="CVE-2011-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0711.html" />
          <reference source="CVE" ref_id="CVE-2011-0712" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0712.html" />
          <reference source="CVE" ref_id="CVE-2011-0726" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0726.html" />
          <reference source="CVE" ref_id="CVE-2011-1013" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1013.html" />
          <reference source="CVE" ref_id="CVE-2011-1016" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1016.html" />
          <reference source="CVE" ref_id="CVE-2011-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1019.html" />
          <reference source="CVE" ref_id="CVE-2011-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1044.html" />
          <reference source="CVE" ref_id="CVE-2011-1079" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1079.html" />
          <reference source="CVE" ref_id="CVE-2011-1080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1080.html" />
          <reference source="CVE" ref_id="CVE-2011-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1093.html" />
          <reference source="CVE" ref_id="CVE-2011-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1573.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* An integer overflow flaw in ib_uverbs_poll_cq() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-4649, Important)

* An integer signedness flaw in drm_modeset_ctl() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2011-1013, Important)

* The Radeon GPU drivers in the Linux kernel were missing sanity checks for
the Anti Aliasing (AA) resolve register values which could allow a local,
unprivileged user to cause a denial of service or escalate their privileges
on systems using a graphics card from the ATI Radeon R300, R400, or R500
family of cards. (CVE-2011-1016, Important)

* A flaw in dccp_rcv_state_process() could allow a remote attacker to
cause a denial of service, even when the socket was already closed.
(CVE-2011-1093, Important)

* A flaw in the Linux kernel's Stream Control Transmission Protocol (SCTP)
implementation could allow a remote attacker to cause a denial of service
if the sysctl "net.sctp.addip_enable" and "auth_enable" variables were
turned on (they are off by default). (CVE-2011-1573, Important)

* A memory leak in the inotify_init() system call. In some cases, it could
leak a group, which could allow a local, unprivileged user to eventually
cause a denial of service. (CVE-2010-4250, Moderate)

* A missing validation of a null-terminated string data structure element
in bnep_sock_ioctl() could allow a local user to cause an information leak
or a denial of service. (CVE-2011-1079, Moderate)

* An information leak in bcm_connect() in the Controller Area Network (CAN)
Broadcast Manager implementation could allow a local, unprivileged user to
leak kernel mode addresses in "/proc/net/can-bcm". (CVE-2010-4565, Low)

* A flaw was found in the Linux kernel's Integrity Measurement Architecture
(IMA) implementation. When SELinux was disabled, adding an IMA rule which
was supposed to be processed by SELinux would cause ima_match_rules() to
always succeed, ignoring any remaining rules. (CVE-2011-0006, Low)

* A missing initialization flaw in the XFS file system implementation could
lead to an information leak. (CVE-2011-0711, Low)

* Buffer overflow flaws in snd_usb_caiaq_audio_init() and
snd_usb_caiaq_midi_init() could allow a local, unprivileged user with
access to a Native Instruments USB audio device to cause a denial of
service or escalate their privileges. (CVE-2011-0712, Low)

* The start_code and end_code values in "/proc/[pid]/stat" were not
protected. In certain scenarios, this flaw could be used to defeat Address
Space Layout Randomization (ASLR). (CVE-2011-0726, Low)

* A flaw in dev_load() could allow a local user who has the CAP_NET_ADMIN
capability to load arbitrary modules from "/lib/modules/", instead of only
netdev modules. (CVE-2011-1019, Low)

* A flaw in ib_uverbs_poll_cq() could allow a local, unprivileged user to
cause an information leak. (CVE-2011-1044, Low)

* A missing validation of a null-terminated string data structure element
in do_replace() could allow a local user who has the CAP_NET_ADMIN
capability to cause an information leak. (CVE-2011-1080, Low)

Red Hat would like to thank Vegard Nossum for reporting CVE-2010-4250;
Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1019, and
CVE-2011-1080; Dan Rosenberg for reporting CVE-2010-4565 and CVE-2011-0711;
Rafael Dominguez Vega for reporting CVE-2011-0712; and Kees Cook for
reporting CVE-2011-0726.

This update also fixes various bugs and adds an enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-10" />
        <updated date="2011-05-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4250.html">CVE-2010-4250</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4565.html">CVE-2010-4565</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4649.html">CVE-2010-4649</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0006.html">CVE-2011-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0711.html">CVE-2011-0711</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0712.html">CVE-2011-0712</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0726.html">CVE-2011-0726</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1013.html">CVE-2011-1013</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1016.html">CVE-2011-1016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1019.html">CVE-2011-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1044.html">CVE-2011-1044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1079.html">CVE-2011-1079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1080.html">CVE-2011-1080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1093.html">CVE-2011-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1573.html">CVE-2011-1573</cve>
                <bugzilla href="http://bugzilla.redhat.com/656830" id="656830">CVE-2010-4250 kernel: inotify memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664544" id="664544">CVE-2010-4565 kernel: CAN info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667912" id="667912">CVE-2011-0006 kernel: ima: fix add LSM rule bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667916" id="667916">CVE-2010-4649 CVE-2011-1044 kernel: IB/uverbs: Handle large number of entries in poll CQ</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670850" id="670850">[6.0] System reset when changing EFI variable on large memory system [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677260" id="677260">CVE-2011-0711 kernel: xfs: prevent leaking uninitialized stack memory in FSGEOMETRY_V1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677881" id="677881">CVE-2011-0712 kernel: ALSA: caiaq - Fix possible string-buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679925" id="679925">CVE-2011-1013 kernel: drm_modeset_ctl signedness issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680000" id="680000">CVE-2011-1016 kernel: drm/radeon/kms: check AA resolve registers on r300</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680360" id="680360">CVE-2011-1019 kernel: CAP_SYS_MODULE bypass via CAP_NET_ADMIN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681260" id="681260">CVE-2011-1079 kernel: bnep device field missing NULL terminator</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681262" id="681262">CVE-2011-1080 kernel: ebtables stack infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682954" id="682954">CVE-2011-1093 kernel: dccp: fix oops on Reset after close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683810" id="683810">[6.1] Common code infrastructure for VLAN null tagging [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684275" id="684275">kernel: BUG: warning at drivers/char/tty_audit.c:55/tty_audit_buf_free() [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684569" id="684569">CVE-2011-0726 kernel: proc: protect mm start_code/end_code in /proc/pid/stat</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691777" id="691777">Bonded and vlan tagged network does not work in KVM guest [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694073" id="694073">82576 stuck after PCI AER error [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694186" id="694186">kswapd0 100% [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695383" id="695383">CVE-2011-1573 kernel: sctp: fix to calc the INIT/INIT-ACK chunk length correctly to set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696889" id="696889">emc_clariion error handler panics with multiple failures [rhel-6.0.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698109" id="698109">Bond interface flapping and increasing rx_missed_errors [rhel-6.0.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498023" comment="kernel-firmware is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498007" comment="kernel-headers is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498005" comment="kernel is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498021" comment="kernel-doc is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498013" comment="kernel-devel is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498025" comment="perf is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498015" comment="kernel-debug is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498017" comment="kernel-kdump is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498011" comment="kernel-debug-devel is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498019" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110498009" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.29.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110506" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0506: rdesktop security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0506.html" />
          <reference source="CVE" ref_id="CVE-2011-1595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1595.html" />
    
    <description>rdesktop is a client for the Remote Desktop Server (previously, Terminal
Server) in Microsoft Windows. It uses the Remote Desktop Protocol (RDP) to
remotely present a user's desktop.

A directory traversal flaw was found in the way rdesktop shared a local
path with a remote server. If a user connects to a malicious server with
rdesktop, the server could use this flaw to cause rdesktop to read and
write to arbitrary, local files accessible to the user running rdesktop.
(CVE-2011-1595)

Red Hat would like to thank Cendio AB for reporting this issue. Cendio AB
acknowledges an anonymous contributor working with the SecuriTeam Secure
Disclosure program as the original reporter.

Users of rdesktop should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-11" />
        <updated date="2011-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1595.html">CVE-2011-1595</cve>
                <bugzilla href="http://bugzilla.redhat.com/676252" id="676252">CVE-2011-1595 rdesktop remote file access</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110506002" comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110506003" comment="rdesktop is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110506008" comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110506009" comment="rdesktop is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110507" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0507: apr security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0507.html" />
          <reference source="CVE" ref_id="CVE-2011-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0419.html" />
    
    <description>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It provides a free library of C data
structures and routines.

It was discovered that the apr_fnmatch() function used an unconstrained
recursion when processing patterns with the '*' wildcard. An attacker could
use this flaw to cause an application using this function, which also
accepted untrusted input as a pattern for matching (such as an httpd server
using the mod_autoindex module), to exhaust all stack memory or use an
excessive amount of CPU time when performing matching. (CVE-2011-0419)

Red Hat would like to thank Maksymilian Arciemowicz for reporting this
issue.

All apr users should upgrade to these updated packages, which contain a
backported patch to correct this issue. Applications using the apr library,
such as httpd, must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-11" />
        <updated date="2011-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0419.html">CVE-2011-0419</cve>
                <bugzilla href="http://bugzilla.redhat.com/703390" id="703390">CVE-2011-0419 apr: unconstrained recursion in apr_fnmatch</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507004" comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507005" comment="apr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507002" comment="apr is earlier than 0:1.2.7-11.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507003" comment="apr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507006" comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507007" comment="apr-docs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507014" comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507015" comment="apr-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507012" comment="apr is earlier than 0:1.3.9-3.el6_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507013" comment="apr is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507019" comment="apr-devel is earlier than 0:0.9.4-25.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507020" comment="apr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110507017" comment="apr is earlier than 0:0.9.4-25.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507018" comment="apr is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110511" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0511: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0511-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0511.html" />
          <reference source="CVE" ref_id="CVE-2011-0579" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0579.html" />
          <reference source="CVE" ref_id="CVE-2011-0618" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0618.html" />
          <reference source="CVE" ref_id="CVE-2011-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0619.html" />
          <reference source="CVE" ref_id="CVE-2011-0620" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0620.html" />
          <reference source="CVE" ref_id="CVE-2011-0621" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0621.html" />
          <reference source="CVE" ref_id="CVE-2011-0622" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0622.html" />
          <reference source="CVE" ref_id="CVE-2011-0623" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0623.html" />
          <reference source="CVE" ref_id="CVE-2011-0624" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0624.html" />
          <reference source="CVE" ref_id="CVE-2011-0625" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0625.html" />
          <reference source="CVE" ref_id="CVE-2011-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0626.html" />
          <reference source="CVE" ref_id="CVE-2011-0627" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0627.html" />
          <reference source="CVE" ref_id="CVE-2011-0628" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0628.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed on the Adobe security page APSB11-12, listed
in the References section.

Multiple security flaws were found in the way flash-plugin displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
potentially, execute arbitrary code when the victim loaded a page
containing the specially-crafted SWF content. (CVE-2011-0618,
CVE-2011-0619, CVE-2011-0620, CVE-2011-0621, CVE-2011-0622, CVE-2011-0623,
CVE-2011-0624, CVE-2011-0625, CVE-2011-0626, CVE-2011-0627)

This update also fixes an information disclosure flaw in flash-plugin.
(CVE-2011-0579)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.181.14.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-13" />
        <updated date="2011-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0579.html">CVE-2011-0579</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0618.html">CVE-2011-0618</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0619.html">CVE-2011-0619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0620.html">CVE-2011-0620</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0621.html">CVE-2011-0621</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0622.html">CVE-2011-0622</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0623.html">CVE-2011-0623</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0624.html">CVE-2011-0624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0625.html">CVE-2011-0625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0626.html">CVE-2011-0626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0627.html">CVE-2011-0627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0628.html">CVE-2011-0628</cve>
                <bugzilla href="http://bugzilla.redhat.com/704368" id="704368">CVE-2011-0579 CVE-2011-0618 CVE-2011-0619 CVE-2011-0620 CVE-2011-0621 CVE-2011-0622 CVE-2011-0623 CVE-2011-0624 CVE-2011-0625 CVE-2011-0626 CVE-2011-0627 CVE-2011-0628 flash-plugin: crash and potential arbitrary code execution (APSB11-12)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110511002" comment="flash-plugin is earlier than 0:10.3.181.14-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110511008" comment="flash-plugin is earlier than 0:10.3.181.14-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110534" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0534: qemu-kvm security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0534-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0534.html" />
          <reference source="CVE" ref_id="CVE-2011-1750" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1750.html" />
          <reference source="CVE" ref_id="CVE-2011-1751" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1751.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that the virtio-blk driver in qemu-kvm did not properly
validate read and write requests from guests. A privileged guest user could
use this flaw to crash the guest or, possibly, execute arbitrary code on
the host. (CVE-2011-1750)

It was found that the PIIX4 Power Management emulation layer in qemu-kvm
did not properly check for hot plug eligibility during device removals. A
privileged guest user could use this flaw to crash the guest or, possibly,
execute arbitrary code on the host. (CVE-2011-1751)

Red Hat would like to thank Nelson Elhage for reporting CVE-2011-1751.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues, and fix the bugs and
add the enhancements noted in the Technical Notes. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1750.html">CVE-2011-1750</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1751.html">CVE-2011-1751</cve>
                <bugzilla href="http://bugzilla.redhat.com/482427" id="482427">support high resolutions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/581750" id="581750">Vhost: Segfault when assigning a none vhostfd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/596610" id="596610">"Guest moved used index from 0 to 61440" if remove virtio serial device before virtserialport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/599307" id="599307">info snapshot return "bdrv_snapshot_list: error -95"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/602205" id="602205">Could not ping guest successfully after changing e1000 MTU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/603413" id="603413">RHEL3.9 guest netdump hung with e1000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/604992" id="604992">index is empty in qemu-doc.html</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607598" id="607598">Incorrect &amp; misleading error reporting when failing to open a drive due to block driver whitelist denial</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/608548" id="608548">QEMU doesn't respect hardware sector size of underlying block device when doing O_DIRECT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/609016" id="609016">incorrect committed memory on idle host</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613893" id="613893">[RFE] qemu-io enable truncate function for qcow2.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/615947" id="615947">RFE QMP: support of query spice for guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616187" id="616187">vmware device emulation enabled but not supported</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616659" id="616659">mrg buffers: migration breaks between systems with/without vhost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616703" id="616703">qemu-kvm core dump with virtio-serial-pci max-port greater than 31</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617119" id="617119">Qemu becomes unresponsive during unattended_installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619168" id="619168">qemu should more clearly indicate internal detection of this host out-of-memory condition at startup..</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619259" id="619259">qemu "-cpu [check | enforce ]" should work even when a model name is not specified on the command line</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623552" id="623552">SCP image fails from host to guest with vhost on when do migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623735" id="623735">hot unplug of vhost net virtio NIC causes qemu segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624396" id="624396">migration failed after hot-unplug virtserialport - Unknown savevm section or instance '0000:00:07.0/virtio-console' 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624572" id="624572">time drift after guest running for more than 12 hours</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624607" id="624607">[qemu] [rhel6] guest installation stop (pause) on 'eother' event over COW disks (thin-provisioning)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624721" id="624721">[qemu] [rhel6] bad error handling when qemu has no 'read' permissions over {kernel,initrd} files [pass boot options]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624767" id="624767">Replace virtio-net TX timer mitigation with bottom half handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624790" id="624790">pass through fails with KVM using Neterion Inc's X3100 Series 10GbE PCIe I/O Virtualized Server Adapter in Multifunction mode.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625319" id="625319">Failed to update the media in floppy device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625333" id="625333">qemu treatment of -nodefconfig and -readconfig problematic for debug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625681" id="625681">RFE QMP: should have command to disconnect and connect network card for whql testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625948" id="625948">qemu exits when hot adding rtl8139 nic to win2k8 guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628634" id="628634">vhost_net: untested error handling in vhost_net_start</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631522" id="631522">spice: prepare qxl for 6.1 update.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632257" id="632257">Duplicate CPU fea.tures in cpu-x86_64.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632458" id="632458">Guest may core dump when booting with spice and qxl.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632722" id="632722">[6.1 FEAT] QEMU static tracing framework</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633394" id="633394">[6.1 FEAT] virtio-blk ioeventfd support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633699" id="633699">Cannot hot-plug nic in windows VM when the vmem is larger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634153" id="634153">coredumped when enable qxl without spice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635354" id="635354">Can not commit copy-on-write image's data to raw backing-image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635418" id="635418">Allow enable/disable ksm per VM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635527" id="635527">KVM:qemu-img re-base poor performance(on local storage) when snapshot to a new disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635954" id="635954">RFE: Assigned device should block migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636494" id="636494">-cpu check  does not correctly enforce CPUID items</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637180" id="637180">watchdog timer isn't reset when qemu resets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637976" id="637976">ksmtuned: give a nicer message if retune is called while ksmtuned is off</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638468" id="638468">[qemu-kvm] bochs vga lfb @ 0xe0000000 causes trouble for hot-plug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639437" id="639437">Incorrect russian vnc keymap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641127" id="641127">qemu-img ignores close() errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642131" id="642131">qemu-kvm aborts of 'qemu_spice_display_create_update: unhandled depth: 0 bits'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643681" id="643681">Do not advertise boot=on capability to libvirt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643687" id="643687">Allow to specify boot order on qemu command line.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643970" id="643970">guest migration turns failed by the end (16G + stress load)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645342" id="645342">Implement QEMU driver for modern sound device like Intel HDA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647307" id="647307">Support slow mapping of PCI Bars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647308" id="647308">Support Westmere as a CPU model or included within existing models..</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647447" id="647447">QMP:  provide a hmp_passthrough command to allow execution of non-converted commands</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647865" id="647865">support 2560x1440 in qxl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648333" id="648333">TCP checksum overflows in qemu's e1000 emulation code when TSO is enabled in guest OS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653582" id="653582">Changing media with -snapshot deletes image file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653972" id="653972">qcow2: Backport performance related patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655735" id="655735">qemu-kvm (or libvirt?) permission denied errors when exporting readonly IDE disk to guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656198" id="656198">Can only see 16 virtio ports while assigned 30 virtio serial ports on commandLine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658288" id="658288">Include (disabled by default) -fake-machine patch on qemu-kvm RPM spec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662633" id="662633">Fix build problem with recent compilers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662701" id="662701">Option -enable-kvm should exit when KVM is unavailable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665025" id="665025">lost double clicks on slow connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665299" id="665299">load vhost-net by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667188" id="667188">device-assignment leaks option ROM memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669268" id="669268">WinXP hang when reboot after setup copies files to the installation folders</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670539" id="670539">Block devices don't implement correct flush error handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670787" id="670787">Hot plug the 14st VF to guest causes guest shut down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671100" id="671100">possible migration failure due to erroneous interpretation of subsection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672187" id="672187">Improper responsive message when shrinking qcow2 image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672191" id="672191">spicevmc: flow control on the spice agent channel is missing in both directions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672229" id="672229">romfile memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672441" id="672441">Tracetool autogenerate qemu-kvm.stp with wrong qemu-kvm path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672720" id="672720">getting 'ctrl buffer too small' error on USB passthrough</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674539" id="674539">slow guests block other guests on the same lan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674562" id="674562">disable vhost-net for rhel5 and older guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675229" id="675229">Install of cpu-x86_64.conf bombs for an out of tree build..</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676015" id="676015">set_link &lt;tap> off not working with vhost-net</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676529" id="676529">core dumped when save snapshot to non-exist disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677222" id="677222">segment fault happens after hot drive add then drive delete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677712" id="677712">disabling vmware device emulation breaks old->new migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678208" id="678208">qemu-kvm hangs when installing guest with -spice option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678524" id="678524">Exec based migration randomly fails, particularly under high load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680058" id="680058">can't hotplug second vf successful with message "Too many open files"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681777" id="681777">floppy I/O error after live migration while floppy in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683295" id="683295">qemu-kvm: Invalid parameter 'vhostforce'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684076" id="684076">Segfault occurred during migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/685147" id="685147">guest with assigned nic got kernel panic when send system_reset signal in QEMU monitor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688058" id="688058">Drive serial number gets truncated</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688119" id="688119">qcow2: qcow2_open doesn't return useful errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688146" id="688146">qcow2: Some paths fail to handle I/O errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688147" id="688147">qcow2: Reads fail with backing file smaller than snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688428" id="688428">qemu-kvm -no-kvm segfaults on pci_add</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688572" id="688572">spice-server does not switch back to server mouse mode if guest spice-agent dies.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690267" id="690267">Backport qemu_get_ram_ptr() performance improvement</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/693741" id="693741">qemu-img re-base  fail with read-only new backing file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694095" id="694095">Migration fails when migrate guest from RHEL6.1 host to RHEL6 host with the same libvirt version</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694196" id="694196">RHEL 6.1 qemu-kvm: Specifying ipv6 addresses breaks migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698906" id="698906">CVE-2011-1750 virtio-blk: heap buffer overflow caused by unaligned requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/699773" id="699773">CVE-2011-1751 qemu: acpi_piix4: missing hotplug check during device removal</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110534007" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345010" comment="qemu-kvm-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110534005" comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345006" comment="qemu-kvm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110534009" comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345008" comment="qemu-img is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110542" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0542: Red Hat Enterprise Linux 6.1 kernel security, bug fix and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0542-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0542.html" />
          <reference source="CVE" ref_id="CVE-2010-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3881.html" />
          <reference source="CVE" ref_id="CVE-2010-4251" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4251.html" />
          <reference source="CVE" ref_id="CVE-2010-4805" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4805.html" />
          <reference source="CVE" ref_id="CVE-2011-0999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0999.html" />
          <reference source="CVE" ref_id="CVE-2011-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1010.html" />
          <reference source="CVE" ref_id="CVE-2011-1023" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1023.html" />
          <reference source="CVE" ref_id="CVE-2011-1082" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1082.html" />
          <reference source="CVE" ref_id="CVE-2011-1090" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1090.html" />
          <reference source="CVE" ref_id="CVE-2011-1163" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1163.html" />
          <reference source="CVE" ref_id="CVE-2011-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1170.html" />
          <reference source="CVE" ref_id="CVE-2011-1171" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1171.html" />
          <reference source="CVE" ref_id="CVE-2011-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1172.html" />
          <reference source="CVE" ref_id="CVE-2011-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1494.html" />
          <reference source="CVE" ref_id="CVE-2011-1495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1495.html" />
          <reference source="CVE" ref_id="CVE-2011-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1581.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Multiple buffer overflow flaws were found in the Linux kernel's
Management Module Support for Message Passing Technology (MPT) based
controllers. A local, unprivileged user could use these flaws to cause a
denial of service, an information leak, or escalate their privileges.
(CVE-2011-1494, CVE-2011-1495, Important)

* A flaw was found in the Linux kernel's Ethernet bonding driver
implementation. Packets coming in from network devices that have more
than 16 receive queues to a bonding interface could cause a denial of
service. (CVE-2011-1581, Important)

* A flaw was found in the Linux kernel's networking subsystem. If the
number of packets received exceeded the receiver's buffer limit, they were
queued in a backlog, consuming memory, instead of being discarded. A remote
attacker could abuse this flaw to cause a denial of service (out-of-memory
condition). (CVE-2010-4251, Moderate)

* A flaw was found in the Linux kernel's Transparent Huge Pages (THP)
implementation. A local, unprivileged user could abuse this flaw to allow
the user stack (when it is using huge pages) to grow and cause a denial of
service. (CVE-2011-0999, Moderate)

* A flaw was found in the transmit methods (xmit) for the loopback and
InfiniBand transports in the Linux kernel's Reliable Datagram Sockets (RDS)
implementation. A local, unprivileged user could use this flaw to cause a
denial of service. (CVE-2011-1023, Moderate)

* A flaw in the Linux kernel's Event Poll (epoll) implementation could
allow a local, unprivileged user to cause a denial of service.
(CVE-2011-1082, Moderate)

* An inconsistency was found in the interaction between the Linux kernel's
method for allocating NFSv4 (Network File System version 4) ACL data and
the method by which it was freed. This inconsistency led to a kernel panic
which could be triggered by a local, unprivileged user with files owned by
said user on an NFSv4 share. (CVE-2011-1090, Moderate)

* A missing validation check was found in the Linux kernel's
mac_partition() implementation, used for supporting file systems created
on Mac OS operating systems. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partitions. (CVE-2011-1010, Low)

* A buffer overflow flaw in the DEC Alpha OSF partition implementation in
the Linux kernel could allow a local attacker to cause an information leak
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1163, Low)

* Missing validations of null-terminated string data structure elements in
the do_replace(), compat_do_replace(), do_ipt_get_ctl(), do_ip6t_get_ctl(),
and do_arpt_get_ctl() functions could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1170,
CVE-2011-1171, CVE-2011-1172, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1494 and
CVE-2011-1495; Nelson Elhage for reporting CVE-2011-1082; Timo Warns for
reporting CVE-2011-1010 and CVE-2011-1163; and Vasiliy Kulikov for
reporting CVE-2011-1170, CVE-2011-1171, and CVE-2011-1172.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.1 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.1 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3881.html">CVE-2010-3881</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4251.html">CVE-2010-4251</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4805.html">CVE-2010-4805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0999.html">CVE-2011-0999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1010.html">CVE-2011-1010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1023.html">CVE-2011-1023</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1082.html">CVE-2011-1082</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1090.html">CVE-2011-1090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1163.html">CVE-2011-1163</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1170.html">CVE-2011-1170</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1171.html">CVE-2011-1171</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1172.html">CVE-2011-1172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1494.html">CVE-2011-1494</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1495.html">CVE-2011-1495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1581.html">CVE-2011-1581</cve>
                <bugzilla href="http://bugzilla.redhat.com/463842" id="463842">[LTC 6.0 FEAT] 201227:NFS over RDMA support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519467" id="519467">new ext4 ioctls, tunables etc undocumented</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/550724" id="550724">xen PV guest kernel 2.6.32 processes lock up in D state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/583064" id="583064">Virtio Net/Disk block devices get wrong parent in node device info</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/588638" id="588638">[abrt] crash in kernel: Your BIOS is broken; DMAR reported at address fed90000 returns all ones!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/590404" id="590404">Garbled image with zc3xx-based webcam</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/591335" id="591335">IPv6 tproxy support is not present in RHEL 6 Beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/591466" id="591466">[abrt] WARNING: at fs/buffer.c:1159 mark_buffer_dirty+0x82/0xa0()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/593766" id="593766">ACPI Error: Illegal I/O port address/length above 64K</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/597333" id="597333">CDTRDSR missing from &lt;asm/termios.h></bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/601849" id="601849">bonding: backport code to allow user-controlled output slave detection.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607262" id="607262">Read from /proc/xen/xenbus does not honor O_NONBLOCK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/610237" id="610237">[6u0] Bonding in ALB mode sends ARP in loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/612436" id="612436">udevd report unexpected exit when guest boot up with nmi_watchdog = 1 and using debugfs tracing KVM (AMD)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616105" id="616105">problems with 64b division on 32b platforms.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616296" id="616296">guest kernel panic when boot with nmi_watchdog=1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616660" id="616660">mrg buffers: migration breaks between systems with/without vhost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617199" id="617199">make exclusively owned pages belong to the local anon_vma on swapin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618175" id="618175">cifs: NT_STATUS_MEDIA_WRITE_PROTECTED not being mapped appropriately to POSIX error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618440" id="618440">jbd2/ocfs2: Fix block checksumming when a buffer is used in several transactions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618602" id="618602">core_pattern handler truncates parameters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619426" id="619426">RHEL UV: kernel patch for kexec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619430" id="619430">Intel HDA audio: popping/clicking sound distortion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619455" id="619455">Host kernel oops after a series of virsh {attach,detach}-device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/621103" id="621103">backport wireless 2.6.32-longterm fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622575" id="622575">networking may go away after migration due to missing arp update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623199" id="623199">Bonded and vlan tagged network does not work in KVM guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623201" id="623201">[RHEL6][Kernel] BUG: spinlock wrong CPU on CPU#2, modprobe/713 (Not tainted)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623968" id="623968">K10 temp support in lm_sensors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624069" id="624069">Upgrading NFS client to 2.6.36 release.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/624628" id="624628">read from virtio-serial returns if the host side is not connect to pipe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625173" id="625173">[RHEL6][Kernel] FATAL: Error inserting ipv6, Cannot allocate memory, causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626561" id="626561">GFS2: [RFE] fallocate support for GFS2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626989" id="626989">block IO controller: Pull in Group idle tunable patches from upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627926" id="627926">[RHEL6.0] e1000e devices fail to initialize interrupts properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627958" id="627958">be2net: A bad assert in processing async messages from NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/628805" id="628805">Fix hot-unplug handling of virtio-console ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629178" id="629178">kernel: Problem with execve(2) reintroduced [rhel-6.1]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629197" id="629197">i8259 state is corrupted during migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629418" id="629418">modpost segmentation fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629423" id="629423">module signing failing on cross-builds due to linker misuse</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629629" id="629629">groups_search() cannot handle large gid correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629715" id="629715">kernel ABI whitelist request for kspice-usb driver [Red Hat]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/629920" id="629920">GFS1 vs GFS2 performance issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630562" id="630562">kernel: additional stack guard patches [rhel-6.1]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631833" id="631833">Big performance regression found on connect/request/response test through IPSEC (openswan) transport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632021" id="632021">Cannot unplug emulated ide and rtl8139 devices in RHEL6 HVM xen guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632631" id="632631">block: fix s390 tape block driver crash that occurs when it switches the IO scheduler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632745" id="632745">[6.1 FEAT] KVM Network Performance: mergeable rx buffers support in vhost-net</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633825" id="633825">kswapd0 100%</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634100" id="634100">migrate_cancel under STRESS caused guest to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634232" id="634232">PATCH: virtio_console: Fix poll blocking even though there is data to read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634303" id="634303">audit filtering on selinux label of userspace audit messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634316" id="634316">tg3: Disable TSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635041" id="635041">GFS2: inode glock stuck without holder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635535" id="635535">Disallow 0-sized writes to virtio ports to go through to host (leading to VM crash)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635537" id="635537">Disable lseek(2) for virtio ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635539" id="635539">WinXP BSOD when boot up with -cpu Penryn</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635853" id="635853">ptrace: the tracee can get the extra trap after PTRACE_DETACH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636291" id="636291">[LSI 6.1 bug] RHEL 6.0 iSCSI offload (cxgb3i) sessions do not log back in after several controller reset cycles [LSI CR184419]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636906" id="636906">32bit compat vectored aio routines are broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/636994" id="636994">[NetApp 6.1 bug] SCSI ALUA handler fails to handle ALUA transitioning properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637278" id="637278">Bug fixes to the 2.6.36 NFS Client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637279" id="637279">Bug fixes to the 2.6.36 NFS Server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637972" id="637972">GFS2: Not enough space reserved in gfs2_write_begin and possibly elsewhere.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638176" id="638176">Replies to broadcast SNMP and NetBIOS queries are dropped</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638269" id="638269">NFS4 clients cannot reclaim locks after server reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/638657" id="638657">GFS2 fatal: filesystem consistency error on rename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639815" id="639815">Ensure we detect removed symbols in check-kabi</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640690" id="640690">Bonded interface doesn't issue IGMP report (join) on slave interface during failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641315" id="641315">Backport upstream cacheing fix for optimizing reads from /proc/vmcore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642206" id="642206">/proc/bus/usb/devices formatting error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643236" id="643236">iscsi: get nopout and conn errors.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643237" id="643237">[NetApp 6.1 bug] regression: allow offlined devs to be set to running</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643290" id="643290">sysctl: bad user of proc_doulongvec_minmax() can oops the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643750" id="643750">virtio_console driver never returns from selecting for write when the queue is full</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643751" id="643751">writing to a virtio serial port while no one is listening on the host side hangs the guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644903" id="644903">Kernel divide by zero in find_busiest_group</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644987" id="644987">Enable extraction of hugepage pfn(s) from /proc/&lt;pid>/pagemap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645287" id="645287">[PATCH] fix size checks for mmap() on /proc/bus/pci files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645793" id="645793">Backport support for TCP thin-streams</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645800" id="645800">Expose hw packet timestamps to network packet capture utilities - backport from 2.6.36</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645824" id="645824">ext4: Don't error out the fs if the user tries to make a file too big</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645898" id="645898">[6.1 FEAT] Port KVM bug fixes for cr_access to RHEL 6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646223" id="646223">cifs: multiuser mount support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646369" id="646369">[kvm] VIRT-IO NIC state is reported as 'unknown' on vm running over RHEL6 host</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646384" id="646384">kernel BUG at mm/migrate.c:113!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646498" id="646498">[6.0] write system call returns with 0 when it should return with EFBIG.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646505" id="646505">Kernel warning at boot:  i7core_edac: probe of 0000:80:14.0 failed with error -22</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647334" id="647334">Allow KSM to split hugepages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647367" id="647367">kvm: guest stale memory after migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647440" id="647440">install_process_keyring() may return wrong error code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648632" id="648632">ext4: writeback performance fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649248" id="649248">ethtool: Provide a default implementation of ethtool_ops::get_drvinfo</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649766" id="649766">DMAR Errors on HP RAID controller with intel_iommu set to on, system hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651005" id="651005">Excessive fpu swap entering and exiting kvm from host userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651021" id="651021">Enable discard/UNMAP/WRITE_SAME for enterprise class arrays</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651332" id="651332">RHEL6.1: EHCI: AMD periodic frame list table quirk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651373" id="651373">NULL pointer dereference in reading vs. truncating race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651584" id="651584">GFS2: BUG_ON kernel panic in gfs2_glock_hold on 2.6.18-226</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651639" id="651639">On AMD host, running an F14 guest with 2 cores assigned hangs for "a long time" (several 10's of minutes) at start of boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651865" id="651865">cifs: bug fixes for 6.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651878" id="651878">cifs: mfsymlinks support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652013" id="652013">If EXT4_EXTENTS_FL flag is not set, the max file size of write() is different than seek().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652371" id="652371">temporary loss of path to SAN results in persistent EIO with msync</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653066" id="653066">Upgrading NFS client to 2.6.37 release</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653068" id="653068">Upgrading NFS server to 2.6.37 release</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653245" id="653245">kernel: restrict unprivileged access to kernel syslog [rhel-6.1]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654532" id="654532">Guest BSOD during installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654665" id="654665">EFI/UEFI page table initialization is incorrect for x86_64 in physical mode.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655231" id="655231">kernel 2.6.32-84.el6 breaks systemtap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655521" id="655521">e1000 driver tracebacks when running under VMware ESX4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655718" id="655718">Win2008 and Win7 fail to load files at the beginning of installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655875" id="655875">jbd2_stats_proc_init has wrong location.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655889" id="655889">kabitool blocks custom kernel builds when kernel version > 2.6.18-53.1.21.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/655935" id="655935">[Emulex 6.1] Update lpfc driver to 8.3.5.28</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656042" id="656042">[RFE] Include autogroup patch to aid in automatic creation of cgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656461" id="656461">cifs: fix problems with filehandle management and reporting of writeback errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656835" id="656835">Memory leak in virtio-console driver if driver probe routine fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656939" id="656939">GFS2: [RFE] glock scalability patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657261" id="657261">Guest kernels need 'noapic' to get kexec working with virtio-blk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657303" id="657303">CVE-2010-4251 CVE-2010-4805 kernel: unlimited socket backlog DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657553" id="657553">[xfstests 243] ext4 incosistency with EOFBLOCK_FL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658248" id="658248">[Emulex 6.1 feat] add BSG and FC Transport patches from Upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658437" id="658437">guest kernel panic when transfering file from host to guest during migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658482" id="658482">block IO controller: Allow creation of cgroup hierarchies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658518" id="658518">neighbour update causes an Oops when using tunnel device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658590" id="658590">GFS2: Use 512 B block sizes to communicate with userland quota tools</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659119" id="659119">khugepaged numa memcg minor memleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659137" id="659137">GFS2: Kernel changes necessary to allow growing completely full filesystems.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659480" id="659480">UV: WAR for interrupt-IOPort deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660674" id="660674">(Mellanox) Add CX3 PCI IDs to mlx4 driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660680" id="660680">iw_cxgb3 advertises incorrect max cq depth causing stalls on large MPI clusters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661048" id="661048">fsck.gfs2 reported statfs error after gfs2_grow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661172" id="661172">MCP55 message on screen at boot even with quiet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662125" id="662125">lldpad is generating selinux errors on 6.0-RC-4.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662589" id="662589">nfs4 callback from client returned to wrong address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662660" id="662660">OS halt on the login screen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/662782" id="662782">Bug fixes to the 2.6.37 NFS Client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663042" id="663042">gfs2 FIEMAP oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663119" id="663119">[Emulex 6.1 feat] Update lpfc driver to 8.3.5.30</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663222" id="663222">[Cisco 6.1 bug] Fix memory leak in fnic and bump version to 1.5.0.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663280" id="663280">Update drivers/media to 2.6.38 codebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663448" id="663448">Bug fixes to the 2.6.37 NFS Server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663538" id="663538">Add AES to CPUID ext_features recognized by kvm..</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663749" id="663749">Btrfs: update to latest upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663755" id="663755">RHEL6 Xen domU freeze after migrate to lower (MHz) CPU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663864" id="663864">kernel: restrict access to /proc/kcore to just elf headers [rhel-6.1]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663994" id="663994">kernels don't build on make-3.82</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664364" id="664364">[6.0] System reset when changing EFI variable on large memory system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664772" id="664772">THP updates from -mm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665110" id="665110">System panic in pskb_expand_head When arp_validate option is specified in bonding ARP monitor mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665169" id="665169">kexec: limit root to call kexec_load()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665360" id="665360">vhost-net/kvm lacks fixes/optimizations in net-next as of Dec 23</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665970" id="665970">KVM crashes inside SeaBIOS when attempting to boot MS-DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666264" id="666264">ftrace: kernel/trace/ring_buffer.c:1987 rb_reserve_next_event</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667186" id="667186">Add upstream performance enhancement to reduce time page fault handler holds mmap_sem semaphore.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667281" id="667281">Bug for patches outside AGP/DRM required for AGP/DRM backport.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667328" id="667328">lib: fix vscnprintf() if @size is == 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667340" id="667340">kexec: Make sure to stop all CPUs before exiting the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667354" id="667354">PV cdrom should be disabled on HVM guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667356" id="667356">xen: unplug the emulated devices at resume time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667359" id="667359">forward port xen pvops changes for evtchn</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667361" id="667361">xenfs: enable for HVM domains too</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667654" id="667654">cifs.upcall not called when mounting second CIFS share from same server using different krb5 credentials</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667661" id="667661">[NetApp 6.1 Bug] Include new NetApp PID entry to the alua_dev_list array in the ALUA hardware handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667686" id="667686">update Documentation/vm/page-types.c to latest upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668114" id="668114">fcoe fails to login with Cisco Eaglehawk switch firmware on VFC shut/no shut</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668340" id="668340">NUMA is not recognized for nec-em25.rhts.eng.bos.redhat.com</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668478" id="668478">PCI sysfs rom file needs owner write access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668825" id="668825">Server cannot boot with kernel-2.6.32-85</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668915" id="668915">setfacl does not update ctime when changing file permission on ext3/4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669252" id="669252">[XEN]RHEL6 guest fail to save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669272" id="669272">xfs: need upstream unaligned aio/dio data corruption fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669373" id="669373">ath9k: inconsistent lock state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669418" id="669418">khugepaged blocking on page locks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669737" id="669737">net: add receive functions that return GRO result codes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669749" id="669749">netif_vdbg() is broken, does not compile if VERBOSE_DEBUG is not defined</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669773" id="669773">disable NUMA for Xen PV guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669787" id="669787">Additional upstream functions that make backporting easier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669813" id="669813">[Broadcom 6.1 feat] bnx2: Update firmware to 6.2.1+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669877" id="669877">GFS2: Blocks not marked free on delete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670063" id="670063">pages stuck in ksm pages_volatile</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670572" id="670572">[NetApp 6.0 Bug] Erroneous TPG ID check in SCSI ALUA Handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670734" id="670734">kernel panic at __rpc_create_common() when mounting nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670907" id="670907">[RHEL6.1][Kernel] BUG: unable to handle kernel NULL pointer dereference, IP: [&lt;ffffffff814115f0>] get_rps_cpu+0x290/0x340</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671147" id="671147">xen 64-bit PV guests fail to save-restore with kernels >= -95</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671161" id="671161">xen microcode WARN on save-restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671267" id="671267">GFS2: allow gfs2 to update quota usage through quotactl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671477" id="671477">[RHEL6.1] possible vmalloc_sync_all() bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672234" id="672234">add POLLPRI to sock_def_readable()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672305" id="672305">Repeatable NFS mount hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672600" id="672600">GFS2: recovery stuck on transaction lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672844" id="672844">section mismatch due to wrong annotation of hugetlb_sysfs_add_hstate()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672937" id="672937">backport set_iounmap_nonlazy() to speedup reading of /proc/vmcore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673496" id="673496">DOMU-HVM FULLVIRT Guest issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673532" id="673532">sfc: the rss_cpus module parameter is ignored</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674064" id="674064">[RHEL6] panic in scsi_init_io() during connectathon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674147" id="674147">SPECsfs NFS V3 workload on RHEL6 running kernels 2.6.32-85 have a massive performance regression due to compact-kswap behavior</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674286" id="674286">mmapping a read only file on a gfs2 filesystem incorrectly acquires an exclusive glock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674409" id="674409">usb: latest xhci fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675102" id="675102">kernel-headers 2.6.32-112.el6 broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675270" id="675270">GFS2: Fails to clear glocks during unmount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675294" id="675294">[RHEL6.1] s/390x hang while running LTP test</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675299" id="675299">'tail -f' waits forever for inotify</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675304" id="675304">Fix potential deadlock in intel-iommu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675745" id="675745">GFS2: panics on quotacheck update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675815" id="675815">Back port Bug fixes from the 2.6.38 NFS Client to the RHEL6 Client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675998" id="675998">/dev/crash does not require CAP_SYS_RAWIO for access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676009" id="676009">xen fix save/restore: unmask event channel for IRQF_TIMER</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676099" id="676099">ip_gre module throws slab corruption errors upon removal from the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676134" id="676134">[Cisco 6.1 Bug Fix] enic: Update enic driver to latest upstream version 2.1.1.10</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676346" id="676346">drivers/xen/events.c clean up section mismatch warning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676579" id="676579">virtio_net: missing schedule on oom</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676875" id="676875">ixgbe: update to 3.0.12-k2  causing a panic on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676948" id="676948">[RFE][6.1] sched: Try not to migrate higher priority RT tasks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677314" id="677314">system_reset cause KVM internal error. Suberror: 2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677532" id="677532">[kdump] WARNING: at kernel/watchdog.c:229 watchdog_overflow_callback+0xa9/0xd0() (Not tainted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677786" id="677786">Panic in get_rps_cpu+0x1ad/0x320 on kvm guest when attempting to run LTP containers test.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678067" id="678067">qeth: allow channel path changes in recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678209" id="678209">CVE-2011-0999 kernel: thp: prevent hugepages during args/env copying into the user stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678357" id="678357">online disk resizing may cause data corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678429" id="678429">[RHEL6.1] [Kernel] When booting previous kernel we are missing the firmware</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679002" id="679002">Wifi connection speed is very slow (intel PRO/Wireless 3945ABG), caused by plcp check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679021" id="679021">semantic difference between mapped file counters of memcg and global VM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679025" id="679025">memcg: upstream backport of various race condition fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679096" id="679096">md: Do not replace request queue lock internally</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679282" id="679282">CVE-2011-1010 kernel: fs/partitions: Validate map_count in Mac partition tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679514" id="679514">qeth: remove needless IPA-commands in offline</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680105" id="680105">[ext4/xfstests] kernel BUG at fs/jbd2/transaction.c:1027!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680126" id="680126">kernel: BUG: warning at drivers/char/tty_audit.c:55/tty_audit_buf_free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680140" id="680140">emc_clariion error handler panics with multiple failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680345" id="680345">CVE-2011-1023 kernel: BUG_ON() in rds_send_xmit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681017" id="681017">82576 stuck after PCI AER error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681133" id="681133">RHEL 5.6 32bit SMP guest hang at boot up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681306" id="681306">tape: deadlock on global work queue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681360" id="681360">block IO controller: Do not use kblockd workqueue for throttle work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681439" id="681439">[ext4/xfstests] 133 task blocked for more than 120 seconds</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681575" id="681575">CVE-2011-1082 kernel: potential kernel deadlock when creating circular epoll file structures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682110" id="682110">kdump dont't work on megaraid_sas</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682265" id="682265">[RHEL 6] libsas: flush initial device discovery before completing ->scan_finished()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682641" id="682641">CVE-2011-1090 kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682726" id="682726">fix skb leak in iwlwifi</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682742" id="682742">iwlagn: Support new 5000 microcode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682831" id="682831">Bad ext4 sync performance on 16 TB GPT partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682951" id="682951">GFS2: umount stuck on gfs2_gl_hash_clear</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683073" id="683073">page_referenced() sometime ignores young bits with THP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684008" id="684008">pE for /sbin/init has special logic that makes it unboundable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684705" id="684705">missed unlock_page() in gfs2_write_begin()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684719" id="684719">Windows guests hang when rebooting with kernel-2.6.32-121.el6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684816" id="684816">occasional NVS 3100 X server lockups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684957" id="684957">RHEL6.1-Alpha: kABI breakage on UV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/685161" id="685161">memcg: premature oom-kill with transparent huge pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/687918" id="687918">thp+memcg-numa: fix BUG at include/linux/mm.h:370!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/687921" id="687921">nfsv4 server leaking struct file on every lock operation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688021" id="688021">CVE-2011-1163 kernel: fs/partitions: Corrupted OSF partition table infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688547" id="688547">RHEL6.1-20110316.1 dell-pe2800 NMI received for unknown reason</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689321" id="689321">CVE-2011-1170 kernel: ipv4: netfilter: arp_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689327" id="689327">CVE-2011-1171 kernel: ipv4: netfilter: ip_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689345" id="689345">CVE-2011-1172 kernel: ipv6: netfilter: ip6_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689551" id="689551">cfq-iosched: Fix a potential crash upon frequent group weight change</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689566" id="689566">mark drivers as tech preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690224" id="690224">Veritas SF 5.1 disagrees about version of symbol aio_complete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690754" id="690754">NFS4 with sec=krb5 does not work with 6.1 beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690865" id="690865">kernel BUG at drivers/gpu/drm/i915/i915_gem.c:4238!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690900" id="690900">slab corruption after seeing some nfs-related BUG: warning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690921" id="690921">Fix compaction deadlock with SLUB and loop over tmpfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691339" id="691339">RHEL6.1 HVM guest with hda+hdc or hdb+hdd crashes; plus hdb/hdd are mapped incorrectly to xvde</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692515" id="692515">sha512hmac expects different checksum, fails on PPC64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694021" id="694021">CVE-2011-1494 CVE-2011-1495 kernel: drivers/scsi/mpt2sas: prevent heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695585" id="695585">[regression] fix be2iscsi rmmod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696029" id="696029">CVE-2011-1581 kernel: bonding: Incorrect TX queue offset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696275" id="696275">[Broadcom 6.1 feat] Support bnx2i hba-mode and non-hba mode for boot in kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696337" id="696337">Bond interface flapping and increasing rx_missed_errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696376" id="696376">server BUG() on receipt of bad NFSv4 lock request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542023" comment="kernel-firmware is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542007" comment="kernel-headers is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542005" comment="kernel is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542025" comment="kernel-doc is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542013" comment="kernel-devel is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542011" comment="perf is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542017" comment="kernel-debug is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542021" comment="kernel-kdump is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542015" comment="kernel-debug-devel is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542019" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110542009" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.0.15.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110545" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0545: squid security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0545-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0545.html" />
          <reference source="CVE" ref_id="CVE-2010-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3072.html" />
    
    <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

It was found that string comparison functions in Squid did not properly
handle the comparisons of NULL and empty strings. A remote, trusted web
client could use this flaw to cause the squid daemon to crash via a
specially-crafted request. (CVE-2010-3072)

This update also fixes the following bugs:

* A small memory leak in Squid caused multiple "ctx: enter level" messages
to be logged to "/var/log/squid/cache.log". This update resolves the memory
leak. (BZ#666533)

* This erratum upgrades Squid to upstream version 3.1.10. This upgraded
version supports the Google Instant service and introduces various code
improvements. (BZ#639365)

Users of squid should upgrade to this updated package, which resolves these
issues. After installing this update, the squid service will be restarted
automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3072.html">CVE-2010-3072</cve>
                <bugzilla href="http://bugzilla.redhat.com/630444" id="630444">CVE-2010-3072 Squid: Denial of service due internal error in string handling (SQUID-2010:3)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639365" id="639365">Rebase squid to version 3.1.10</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666533" id="666533">small memleak in squid-3.1.4</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110545005" comment="squid is earlier than 7:3.1.10-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110545006" comment="squid is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110554" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0554: python security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0554-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0554.html" />
          <reference source="CVE" ref_id="CVE-2010-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3493.html" />
          <reference source="CVE" ref_id="CVE-2011-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1015.html" />
          <reference source="CVE" ref_id="CVE-2011-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1521.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

A flaw was found in the Python urllib and urllib2 libraries where they
would not differentiate between different target URLs when handling
automatic redirects. This caused Python applications using these modules to
follow any new URL that they understood, including the "file://" URL type.
This could allow a remote server to force a local Python application to
read a local file instead of the remote one, possibly exposing local files
that were not meant to be exposed. (CVE-2011-1521)

A race condition was found in the way the Python smtpd module handled new
connections. A remote user could use this flaw to cause a Python script
using the smtpd module to terminate. (CVE-2010-3493)

An information disclosure flaw was found in the way the Python
CGIHTTPServer module processed certain HTTP GET requests. A remote attacker
could use a specially-crafted request to obtain the CGI script's source
code. (CVE-2011-1015)

This erratum also upgrades Python to upstream version 2.6.6, and includes a
number of bug fixes and enhancements. Documentation for these bug fixes
and enhancements is available from the Technical Notes document, linked to
in the References section.

All users of Python are advised to upgrade to these updated packages, which
correct these issues, and fix the bugs and add the enhancements noted in
the Technical Notes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3493.html">CVE-2010-3493</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1015.html">CVE-2011-1015</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1521.html">CVE-2011-1521</cve>
                <bugzilla href="http://bugzilla.redhat.com/603073" id="603073">python >>> help() >>> modules command traceback when used without DISPLAY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/614680" id="614680">Try to print repr() when a fatal garbage collection assertion fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625393" id="625393">adjust test_commands unit test to the updated output of the ls command</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/625395" id="625395">include the tests/data directory in the python-test rpm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626756" id="626756">test_dbm fails on ppc64 &amp; s390x</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627301" id="627301">Rebase python from 2.6.5 to 2.6.6 in RHEL 6.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632200" id="632200">CVE-2010-3493 Python: SMTP proxy RFC 2821 module DoS (uncaught exception) (Issue #9129)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634944" id="634944">rpmlint errors and warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639392" id="639392">Generating python backtrace with "py-bt" fails with a traceback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649274" id="649274">Infinite recursion in urllib2 on basicauth failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/650588" id="650588">subprocess fails in select when descriptors are large (rhel6)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669847" id="669847">urllib2's AbstractBasicAuthHandler is limited to 6 requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680094" id="680094">CVE-2011-1015 python (CGIHTTPServer): CGI script source code disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684991" id="684991">python update causes rhythmbox to crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690315" id="690315">python occasionally fails to build on machines with more than one core</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690560" id="690560">CVE-2011-1521 python (urllib, urllib2): Improper management of ftp:// and file:// URL schemes (Issue #11662)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554005" comment="python-docs is earlier than 0:2.6.6-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554006" comment="python-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554009" comment="python-devel is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554010" comment="python-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554013" comment="python-libs is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554014" comment="python-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554015" comment="python-test is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554016" comment="python-test is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554017" comment="tkinter is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554018" comment="tkinter is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554007" comment="python is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554008" comment="python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110554011" comment="python-tools is earlier than 0:2.6.6-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110554012" comment="python-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110558" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0558: perl security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0558-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0558.html" />
          <reference source="CVE" ref_id="CVE-2010-2761" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2761.html" />
          <reference source="CVE" ref_id="CVE-2010-4410" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4410.html" />
          <reference source="CVE" ref_id="CVE-2011-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1487.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and web programming. The Perl CGI module provides
resources for preparing and processing Common Gateway Interface (CGI) based
HTTP requests and responses.

It was found that the Perl CGI module used a hard-coded value for the MIME
boundary string in multipart/x-mixed-replace content. A remote attacker
could possibly use this flaw to conduct an HTTP response splitting attack
via a specially-crafted HTTP request. (CVE-2010-2761)

A CRLF injection flaw was found in the way the Perl CGI module processed a
sequence of non-whitespace preceded by newline characters in the header. A
remote attacker could use this flaw to conduct an HTTP response splitting
attack via a specially-crafted sequence of characters provided to the CGI
module. (CVE-2010-4410)

It was found that certain Perl string manipulation functions (such as uc()
and lc()) failed to preserve the taint bit. A remote attacker could use
this flaw to bypass the Perl taint mode protection mechanism in scripts
that use the affected functions to process tainted input. (CVE-2011-1487)

These packages upgrade the CGI module to version 3.51. Refer to the CGI
module's Changes file, linked to in the References, for a full list of
changes.

This update also fixes the following bugs:

* When using the "threads" module, an attempt to send a signal to a thread
that did not have a signal handler specified caused the perl interpreter to
terminate unexpectedly with a segmentation fault. With this update, the
"threads" module has been updated to upstream version 1.82, which fixes
this bug. As a result, sending a signal to a thread that does not have the
signal handler specified no longer causes perl to crash. (BZ#626330)

* Prior to this update, the perl packages did not require the Digest::SHA
module as a dependency. Consequent to this, when a user started the cpan
command line interface and attempted to download a distribution from CPAN,
they may have been presented with the following message:

CPAN: checksum security checks disabled because Digest::SHA not installed.
Please consider installing the Digest::SHA module.

This update corrects the spec file for the perl package to require the
perl-Digest-SHA package as a dependency, and cpan no longer displays the
above message. (BZ#640716)

* When using the "threads" module, continual creation and destruction of
threads could cause the Perl program to consume an increasing amount of
memory. With this update, the underlying source code has been corrected to
free the allocated memory when a thread is destroyed, and the continual
creation and destruction of threads in Perl programs no longer leads to
memory leaks. (BZ#640720)

* Due to a packaging error, the perl packages did not include the
"NDBM_File" module. This update corrects this error, and "NDBM_File" is now
included as expected. (BZ#640729)

* Prior to this update, the prove(1) manual page and the "prove --help"
command listed "--fork" as a valid command line option. However, version
3.17 of the Test::Harness distribution removed the support for the
fork-based parallel testing, and the prove utility thus no longer supports
this option. This update corrects both the manual page and the output of
the "prove --help" command, so that "--fork" is no longer included in the
list of available command line options. (BZ#609492)

Users of Perl, especially those of Perl threads, are advised to upgrade to
these updated packages, which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-2761.html">CVE-2010-2761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4410.html">CVE-2010-4410</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1487.html">CVE-2011-1487</cve>
                <bugzilla href="http://bugzilla.redhat.com/609492" id="609492">unknown option fork with prove</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626330" id="626330">Sending signal to thread without signal handler in thread causes perl to segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640716" id="640716">Let perl-CPAN Require: perl(Digest::SHA)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640720" id="640720">Thread desctructor leaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640729" id="640729">NDBM_File module is missing in perl core</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658976" id="658976">perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692898" id="692898">CVE-2011-1487 perl: lc(), uc() routines are laundering tainted data</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558091" comment="perl-core is earlier than 4:5.10.1-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558092" comment="perl-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558081" comment="perl-CPANPLUS is earlier than 4:0.88-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558082" comment="perl-CPANPLUS is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558079" comment="perl-File-Fetch is earlier than 4:0.26-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558080" comment="perl-File-Fetch is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558071" comment="perl-CGI is earlier than 4:3.51-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558072" comment="perl-CGI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558069" comment="perl-Log-Message is earlier than 4:0.02-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558070" comment="perl-Log-Message is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558059" comment="perl-Module-CoreList is earlier than 4:2.18-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558060" comment="perl-Module-CoreList is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558055" comment="perl-Compress-Raw-Zlib is earlier than 4:2.023-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558056" comment="perl-Compress-Raw-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558021" comment="perl-Module-Build is earlier than 4:0.3500-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558022" comment="perl-Module-Build is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558077" comment="perl-libs is earlier than 4:5.10.1-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558078" comment="perl-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558063" comment="perl-parent is earlier than 4:0.221-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558064" comment="perl-parent is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558049" comment="perl-Term-UI is earlier than 4:0.20-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558050" comment="perl-Term-UI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558043" comment="perl-Object-Accessor is earlier than 4:0.34-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558044" comment="perl-Object-Accessor is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558039" comment="perl-devel is earlier than 4:5.10.1-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558040" comment="perl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558035" comment="perl-Time-Piece is earlier than 4:1.15-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558036" comment="perl-Time-Piece is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558033" comment="perl-Pod-Escapes is earlier than 4:1.04-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558034" comment="perl-Pod-Escapes is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558029" comment="perl-ExtUtils-CBuilder is earlier than 4:0.27-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558030" comment="perl-ExtUtils-CBuilder is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558025" comment="perl-Digest-SHA is earlier than 4:5.47-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558026" comment="perl-Digest-SHA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558011" comment="perl-Test-Harness is earlier than 4:3.17-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558012" comment="perl-Test-Harness is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558083" comment="perl-Archive-Extract is earlier than 4:0.38-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558084" comment="perl-Archive-Extract is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558061" comment="perl-suidperl is earlier than 4:5.10.1-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558062" comment="perl-suidperl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558053" comment="perl-Parse-CPAN-Meta is earlier than 4:1.40-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558054" comment="perl-Parse-CPAN-Meta is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558031" comment="perl-ExtUtils-ParseXS is earlier than 4:2.2003.0-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558032" comment="perl-ExtUtils-ParseXS is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558015" comment="perl-IPC-Cmd is earlier than 4:0.56-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558016" comment="perl-IPC-Cmd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558013" comment="perl-Test-Simple is earlier than 4:0.92-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558014" comment="perl-Test-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558085" comment="perl-Module-Pluggable is earlier than 4:3.90-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558086" comment="perl-Module-Pluggable is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558073" comment="perl-ExtUtils-MakeMaker is earlier than 4:6.55-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558074" comment="perl-ExtUtils-MakeMaker is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558067" comment="perl-CPAN is earlier than 4:1.9402-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558068" comment="perl-CPAN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558065" comment="perl-Compress-Zlib is earlier than 4:2.020-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558066" comment="perl-Compress-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558057" comment="perl-IO-Compress-Zlib is earlier than 4:2.020-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558058" comment="perl-IO-Compress-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558041" comment="perl-Pod-Simple is earlier than 4:3.13-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558042" comment="perl-Pod-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558007" comment="perl-Module-Load-Conditional is earlier than 4:0.30-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558008" comment="perl-Module-Load-Conditional is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558019" comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558020" comment="perl-Time-HiRes is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558075" comment="perl-ExtUtils-Embed is earlier than 4:1.28-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558076" comment="perl-ExtUtils-Embed is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558047" comment="perl-Locale-Maketext-Simple is earlier than 4:0.18-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558048" comment="perl-Locale-Maketext-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558045" comment="perl-IO-Compress-Base is earlier than 4:2.020-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558046" comment="perl-IO-Compress-Base is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558023" comment="perl-version is earlier than 4:0.77-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558024" comment="perl-version is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558009" comment="perl-Module-Loaded is earlier than 4:0.02-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558010" comment="perl-Module-Loaded is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558005" comment="perl is earlier than 4:5.10.1-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558006" comment="perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558087" comment="perl-Log-Message-Simple is earlier than 4:0.04-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558088" comment="perl-Log-Message-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558051" comment="perl-IO-Zlib is earlier than 4:1.09-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558052" comment="perl-IO-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558037" comment="perl-Module-Load is earlier than 4:0.16-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558038" comment="perl-Module-Load is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558027" comment="perl-Params-Check is earlier than 4:0.26-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558028" comment="perl-Params-Check is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558089" comment="perl-Package-Constants is earlier than 4:0.02-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558090" comment="perl-Package-Constants is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110558017" comment="perl-Archive-Tar is earlier than 4:1.58-119.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558018" comment="perl-Archive-Tar is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110560" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0560: sssd security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0560-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0560.html" />
          <reference source="CVE" ref_id="CVE-2010-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4341.html" />
    
    <description>The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.

A flaw was found in the SSSD PAM responder that could allow a local
attacker to crash SSSD via a carefully-crafted packet. With SSSD
unresponsive, legitimate users could be denied the ability to log in to the
system. (CVE-2010-4341)

Red Hat would like to thank Sebastian Krahmer for reporting this issue.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

Users of SSSD should upgrade to these updated packages, which upgrade SSSD
to upstream version 1.5.1 to correct this issue, and fix the bugs and add
the enhancements noted in the Technical Notes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4341.html">CVE-2010-4341</cve>
                <bugzilla href="http://bugzilla.redhat.com/442680" id="442680">Better support for Kerberos ticket cache management</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598501" id="598501">SSSD doesn't follow LDAP referrals when using non-anonymous bind</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633406" id="633406">the krb5 locator plugin isn't packaged for multilib</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633487" id="633487">SSSD initgroups does not behave as expected</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640602" id="640602">sssd is not escaping correctly LDAP searches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/644072" id="644072">Rebase SSSD to 1.5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645438" id="645438">NSS responder dies if DP dies during a request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645449" id="645449">'getent passwd &lt;username>' returns nothing if its uidNumber gt 2147483647.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/647816" id="647816">Login screen freezes for more than 2mins when configured SSSD for proxy auth.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/649286" id="649286">SSSD will sometimes lose groups from the cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658158" id="658158">sssd stops on upgrade</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659401" id="659401">SSSD shutdown sometimes hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660323" id="660323">Provide an option to specify DNS domain for service discovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661163" id="661163">CVE-2010-4341 sssd: DoS in sssd PAM responder can prevent logins</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667059" id="667059">nss client blocks when enumerating local domain after restart.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667326" id="667326">'-s' option in sss_obfuscate command is a bit redundant.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667349" id="667349">Obfuscated passwords can kill LDAP provider if OpenLDAP uses NSS.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670511" id="670511">SSSD and sftp-only jailed users with pubkey login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670763" id="670763">Missing primary group with simple access provider.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670804" id="670804">Nested groups are not unrolled during the first enumeration.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671478" id="671478">authconfig-tui/gtk removes "ldap_user_home_directory" from sssd.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674141" id="674141">Traceback call messages displayed while "sss_obfuscate" command is executed as a non-root user.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674164" id="674164">sss_obfuscate fails if there's no domain named "default".</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674172" id="674172">Group members are not sanitized in nested group processing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674515" id="674515">-p option always uses empty string to obfuscate password.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675284" id="675284">"no matching rule" message logged on all successful requests.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676401" id="676401">Remove HBAC time rules from SSSD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676911" id="676911">SSSD attempts to use START_TLS over LDAPS for authentication</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677318" id="677318">Does not read renewable ccache at startup.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677588" id="677588">sssd crashes at the next tgt renewals it tries.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678091" id="678091">SSSD in 6.0 can not locate HBAC rules from FreeIPAv2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678410" id="678410">name service caches names, so id command shows recently deleted users</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678593" id="678593">User information not updated on login for secondary domains</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678614" id="678614">SSSD needs to look at IPA's compat tree for netgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678777" id="678777">IPA provider does not update removed group memberships on initgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679082" id="679082">SSSD IPA provider should honor the krb5_realm option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680367" id="680367">sssd not thread-safe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682340" id="682340">sssd-be segmentation fault - ipa-client on ipa-server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682807" id="682807">sssd_nss core dumps with certain lookups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682850" id="682850">IPA provider should use realm instead of ipa_domain for base DN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683158" id="683158">multiple problems with sssd + ldap (Active-Directory) and groups members.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683255" id="683255">sudo/ldap lookup via sssd gets stuck for 5min waiting on netgroup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683860" id="683860">sssd 1.5.1-9 breaks AD authentication</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683885" id="683885">SSSD should skip over groups with multiple names</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688491" id="688491">authconfig fails when access_provider is set as krb5 in sssd.conf.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689886" id="689886">group memberships are not populated correctly during IPA provider initgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690131" id="690131">Traceback messages seen while interrupting sss_obfuscate using ctrl+d.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690421" id="690421">[abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690866" id="690866">Groups with a zero-length memberuid attribute can cause SSSD to stop caching and responding to requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691678" id="691678">SSSD needs to fall back to 'cn' for GECOS information (was: SSSD configuration problem when configured with MSAD)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692472" id="692472">Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694146" id="694146">SSSD consumes GBs of RAM, possible memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694444" id="694444">Unable to resolve SRV record when called with _srv_,&lt;fixed ldap uri> in ldap_uri</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694783" id="694783">SSSD crashes during getent when anonymous bind is disabled.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696972" id="696972">[REGRESSION] Filters not honoured against fully-qualified users.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/701700" id="701700">sssd client libraries use select() but should use poll() instead</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110560005" comment="sssd is earlier than 0:1.5.1-34.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110560006" comment="sssd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110560007" comment="sssd-client is earlier than 0:1.5.1-34.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110560008" comment="sssd-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110560009" comment="sssd-tools is earlier than 0:1.5.1-34.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110560010" comment="sssd-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110568" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0568: eclipse security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0568-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0568.html" />
          <reference source="CVE" ref_id="CVE-2010-4647" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4647.html" />
    
    <description>The Eclipse software development environment provides a set of tools for
C/C++ and Java development.

A cross-site scripting (XSS) flaw was found in the Eclipse Help Contents
web application. An attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted Eclipse Help URL. (CVE-2010-4647)

The following Eclipse packages have been upgraded to the versions found in
the official upstream Eclipse Helios SR1 release, providing a number of
bug fixes and enhancements over the previous versions:

* eclipse to 3.6.1. (BZ#656329)
* eclipse-cdt to 7.0.1. (BZ#656333)
* eclipse-birt to 2.6.0. (BZ#656391)
* eclipse-emf to 2.6.0. (BZ#656344)
* eclipse-gef to 3.6.1. (BZ#656347)
* eclipse-mylyn to 3.4.2. (BZ#656337)
* eclipse-rse to 3.2. (BZ#656338)
* eclipse-dtp to 1.8.1. (BZ#656397)
* eclipse-changelog to 2.7.0. (BZ#669499)
* eclipse-valgrind to 0.6.1. (BZ#669460)
* eclipse-callgraph to 0.6.1. (BZ#669462)
* eclipse-oprofile to 0.6.1. (BZ#670228)
* eclipse-linuxprofilingframework to 0.6.1. (BZ#669461)

In addition, the following updates were made to the dependencies of the
Eclipse packages above:

* icu4j to 4.2.1. (BZ#656342)
* sat4j to 2.2.0. (BZ#661842)
* objectweb-asm to 3.2. (BZ#664019)
* jetty-eclipse to 6.1.24. (BZ#661845)

This update includes numerous upstream bug fixes and enhancements, such as:

* The Eclipse IDE and Java Development Tools (JDT):

- projects and folders can filter out resources in the workspace.
- new virtual folder and linked files support.
- the full set of UNIX file permissions is now supported.
- addition of the stop button to cancel long-running wizard tasks.
- Java editor now shows multiple quick-fixes via problem hover.
- new support for running JUnit version 4 tests.
- over 200 upstream bug fixes.

* The Eclipse C/C++ Development Tooling (CDT):

- new Codan framework has been added for static code analysis.
- refactoring improvements such as stored refactoring history.
- compile and build errors now highlighted in the build console.
- switch to the new DSF debugger framework.
- new template view support.
- over 600 upstream bug fixes.

This update also fixes the following bugs:

* Incorrect URIs for GNU Tools in the "Help Contents" window have been
fixed. (BZ#622713)

* The profiling of binaries did not work if an Eclipse project was not in
an Eclipse workspace. This update adds an automated test for external
project profiling, which corrects this issue. (BZ#622867)

* Running a C/C++ application in Eclipse successfully terminated, but
returned an I/O exception not related to the application itself in the
Error Log window. With this update, the exception is no longer returned.
(BZ#668890)

* The eclipse-mylyn package showed a "20100916-0100-e3x" qualifier. The
qualifier has been modified to "v20100902-0100-e3x" to match the upstream
version of eclipse-mylyn. (BZ#669819)

* Installing the eclipse-mylyn package failed and returned a "Resource
temporarily unavailable" error message due to a bug in the packaging. This
update fixes this bug and installation now works as expected. (BZ#673174)

* Building the eclipse-cdt package could fail due to an incorrect
interaction with the local file system. Interaction with the local file
system is now prevented and the build no longer fails. (BZ#678364)

* The libhover plug-in, provided by the eclipse-cdt package, used binary
data to search for hover topics. The data location was specified externally
as a URL which could cause an exception to occur on a system with no
Internet access. This update modifies the plug-in so that it pulls the
needed data from a local location. (BZ#679543)

Users of eclipse should upgrade to these updated packages, which correct
these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4647.html">CVE-2010-4647</cve>
                <bugzilla href="http://bugzilla.redhat.com/622713" id="622713">Help Contents: Wrong URIs to GNU Tools</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622867" id="622867">Profiling of binaries does not work if Eclipse project is NOT in Eclipse workspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656329" id="656329">[eclipse] Re-base to Helios SR1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656333" id="656333">[eclipse-cdt] Re-base to Helios SR1(7.0.1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656337" id="656337">[eclipse-mylyn] Re-base to Helios SR1(3.4.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656338" id="656338">[eclipse-rse] Re-base to Helios SR1(3.2.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656342" id="656342">Re-base icu4j to 4.2.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656344" id="656344">[eclipse-emf] Re-base to Helios SR1(2.6.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656347" id="656347">[eclipse-gef] Re-base to Helios SR1(3.6.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656391" id="656391">Re-base eclipse-birt to Helios SR1(2.6.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656397" id="656397">[eclipse-dtp] Re-base to Helios SR1(1.8.0)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661842" id="661842">Re-base to sat4j 2.2.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661845" id="661845">Re-base to jetty-eclipse 6.1.24</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661901" id="661901">CVE-2010-4647 eclipse: Help Content web application vulnerable to multiple XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664019" id="664019">Re-base to objectweb-asm 3.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668890" id="668890">Debug core logs spawner IO exception when running C/C++ executable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669460" id="669460">[eclipse-valgrind] Update to work with updated eclipse-birt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669461" id="669461">[eclipse-linuxprofilingframework] new version to allow updated eclipse-valgrind</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669462" id="669462">[eclipse-callgraph] Updates to callgraph to work with newer GEF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669499" id="669499">[eclipse-changelog] Update eclipse-changelog plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669819" id="669819">Update eclipse-mylyn qualifier to 20100916-0100-e3x</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670228" id="670228">[eclipse-oprofile] Re-base to upstream 0.6.1 release</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673174" id="673174">error: unpacking of archive failed: cpio: lstat failed - Resource temporarily unavailable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678364" id="678364">eclipse-cdt build touching local filesystem</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568005" comment="jetty-eclipse is earlier than 0:6.1.24-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568006" comment="jetty-eclipse is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568007" comment="eclipse-rse is earlier than 0:3.2-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568008" comment="eclipse-rse is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568009" comment="sat4j is earlier than 0:2.2.0-4.0.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568010" comment="sat4j is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568013" comment="objectweb-asm-javadoc is earlier than 0:3.2-2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568014" comment="objectweb-asm-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568011" comment="objectweb-asm is earlier than 0:3.2-2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568012" comment="objectweb-asm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568017" comment="eclipse-emf-xsd is earlier than 0:2.6.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568018" comment="eclipse-emf-xsd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568019" comment="eclipse-emf-xsd-sdk is earlier than 0:2.6.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568020" comment="eclipse-emf-xsd-sdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568015" comment="eclipse-emf is earlier than 0:2.6.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568016" comment="eclipse-emf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568021" comment="eclipse-emf-examples is earlier than 0:2.6.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568022" comment="eclipse-emf-examples is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568023" comment="eclipse-emf-sdk is earlier than 0:2.6.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568024" comment="eclipse-emf-sdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568025" comment="eclipse-dtp is earlier than 0:1.8.1-1.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568026" comment="eclipse-dtp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568027" comment="eclipse-birt is earlier than 0:2.6.0-1.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568028" comment="eclipse-birt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568029" comment="eclipse-linuxprofilingframework is earlier than 0:0.6.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568030" comment="eclipse-linuxprofilingframework is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568031" comment="eclipse-callgraph is earlier than 0:0.6.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568032" comment="eclipse-callgraph is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568033" comment="eclipse-changelog is earlier than 1:2.7.0-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568034" comment="eclipse-changelog is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568035" comment="eclipse-valgrind is earlier than 0:0.6.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568036" comment="eclipse-valgrind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568037" comment="eclipse-oprofile is earlier than 0:0.6.1-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568038" comment="eclipse-oprofile is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568043" comment="icu4j-eclipse is earlier than 1:4.2.1-5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568044" comment="icu4j-eclipse is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568041" comment="icu4j-javadoc is earlier than 1:4.2.1-5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568042" comment="icu4j-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568039" comment="icu4j is earlier than 1:4.2.1-5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568040" comment="icu4j is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568045" comment="eclipse-gef is earlier than 0:3.6.1-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568046" comment="eclipse-gef is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568047" comment="eclipse-gef-sdk is earlier than 0:3.6.1-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568048" comment="eclipse-gef-sdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568049" comment="eclipse-gef-examples is earlier than 0:3.6.1-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568050" comment="eclipse-gef-examples is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568055" comment="eclipse-jdt is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568056" comment="eclipse-jdt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568057" comment="eclipse-swt is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568058" comment="eclipse-swt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568053" comment="eclipse-pde is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568054" comment="eclipse-pde is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568061" comment="eclipse-platform is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568062" comment="eclipse-platform is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568059" comment="eclipse-rcp is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568060" comment="eclipse-rcp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568051" comment="eclipse is earlier than 1:3.6.1-6.13.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568052" comment="eclipse is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568065" comment="eclipse-mylyn-trac is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568066" comment="eclipse-mylyn-trac is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568075" comment="eclipse-mylyn-java is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568076" comment="eclipse-mylyn-java is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568069" comment="eclipse-mylyn-webtasks is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568070" comment="eclipse-mylyn-webtasks is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568067" comment="eclipse-mylyn-pde is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568068" comment="eclipse-mylyn-pde is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568063" comment="eclipse-mylyn is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568064" comment="eclipse-mylyn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568071" comment="eclipse-mylyn-wikitext is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568072" comment="eclipse-mylyn-wikitext is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568073" comment="eclipse-mylyn-cdt is earlier than 0:3.4.2-9.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568074" comment="eclipse-mylyn-cdt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568077" comment="eclipse-cdt is earlier than 1:7.0.1-4.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568078" comment="eclipse-cdt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568081" comment="eclipse-cdt-sdk is earlier than 1:7.0.1-4.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568082" comment="eclipse-cdt-sdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110568079" comment="eclipse-cdt-parsers is earlier than 1:7.0.1-4.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110568080" comment="eclipse-cdt-parsers is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110586" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0586: libguestfs security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0586.html" />
          <reference source="CVE" ref_id="CVE-2010-3851" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3851.html" />
    
    <description>libguestfs is a library for accessing and modifying guest disk images.

libguestfs relied on the format auto-detection in QEMU rather than
allowing the guest image file format to be specified. A privileged guest
user could potentially use this flaw to read arbitrary files on the host
that were accessible to a user on that host who was running a program that
utilized the libguestfs library. (CVE-2010-3851)

This erratum upgrades libguestfs to upstream version 1.7.17, which includes
a number of bug fixes and one enhancement. Documentation for these bug
fixes and this enhancement is provided in the Technical Notes document,
linked to in the References section.

All libguestfs users are advised to upgrade to these updated packages,
which correct this issue, and fix the bugs and add the enhancement noted
in the Technical Notes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3851.html">CVE-2010-3851</cve>
                <bugzilla href="http://bugzilla.redhat.com/600144" id="600144">document that mkmountpoint and umount-all cannot be mixed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/612308" id="612308">qemu -net / vlan option deprecated.  Use -netdev instead.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/613593" id="613593">Rebase libguestfs in RHEL 6.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/615223" id="615223">vfs-type could not read just-created filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/617440" id="617440">guestfish: fails to tilde expand '~' when the $HOME env is unset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627468" id="627468">[RFE]It's better to emphasize "libguestfs-winsupport" in V2V manpage or error output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627832" id="627832">[RFE] guestfish should print outputs in a suitable base (eg. octal for modes)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627833" id="627833">get-e2uuid should use blkid instead of "tune2fs -l" to get filesystem UUID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633174" id="633174">some guestfish sub commands can not handle special files properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639601" id="639601">"virt-ls" command failed to parse domain name "#"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639602" id="639602">""virt-list-filesystems" fails to parse the command line argument if the domain name is "#".</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643958" id="643958">CVE-2010-3851 libguestfs: missing disk format specifier when adding a disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657472" id="657472">checksum: wrong check sum type causes umount to fail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657502" id="657502">virt-inspector depends on EPEL package perl-String-ShellQuote but does not require it</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666577" id="666577">libguestfs: unknown filesystem /dev/fd0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666579" id="666579">libguestfs: unknown filesystem /dev/hd{x} (cdrom)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668115" id="668115">virt-filesystems command fails on guest with corrupt filesystem label</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668611" id="668611">guestfish -i is trying to mount all mounts from /etc/fstab and fails with an error when device doesn't exists</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673477" id="673477">Add a grep-friendly string to LIBGUESTFS_TRACE output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673721" id="673721">Typo in virt-make-fs manual page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676788" id="676788">libguestfs trace segfaults when list-filesystems returns error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677616" id="677616">appliance doesn't include augeas device_map lens</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691724" id="691724">virt-inspector reports unknown filesystem /dev/vda1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695138" id="695138">Remove dependency on gfs2-utils</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586005" comment="libguestfs is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586006" comment="libguestfs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586031" comment="ruby-libguestfs is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586032" comment="ruby-libguestfs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586025" comment="libguestfs-mount is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586026" comment="libguestfs-mount is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586011" comment="libguestfs-javadoc is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586012" comment="libguestfs-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586009" comment="libguestfs-tools is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586010" comment="libguestfs-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586019" comment="libguestfs-tools-c is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586020" comment="libguestfs-tools-c is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586029" comment="ocaml-libguestfs-devel is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586030" comment="ocaml-libguestfs-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586021" comment="guestfish is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586022" comment="guestfish is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586013" comment="ocaml-libguestfs is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586014" comment="ocaml-libguestfs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586015" comment="python-libguestfs is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586016" comment="python-libguestfs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586023" comment="perl-Sys-Guestfs is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586024" comment="perl-Sys-Guestfs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586027" comment="libguestfs-java-devel is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586028" comment="libguestfs-java-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586017" comment="libguestfs-java is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586018" comment="libguestfs-java is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110586007" comment="libguestfs-devel is earlier than 1:1.7.17-17.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110586008" comment="libguestfs-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110599" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0599: sudo security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0599-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0599.html" />
          <reference source="CVE" ref_id="CVE-2011-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0010.html" />
    
    <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root.

A flaw was found in the sudo password checking logic. In configurations
where the sudoers settings allowed a user to run a command using sudo with
only the group ID changed, sudo failed to prompt for the user's password
before running the specified command with the elevated group privileges.
(CVE-2011-0010)

This update also fixes the following bugs:

* When the "/etc/sudoers" file contained entries with multiple hosts,
running the "sudo -l" command incorrectly reported that a certain user does
not have permissions to use sudo on the system. With this update, running
the "sudo -l" command now produces the correct output. (BZ#603823)

* Prior to this update, the manual page for sudoers.ldap was not installed,
even though it contains important information on how to set up an LDAP
(Lightweight Directory Access Protocol) sudoers source, and other documents
refer to it. With this update, the manual page is now properly included in
the package. Additionally, various POD files have been removed from the
package, as they are required for build purposes only. (BZ#634159)

* The previous version of sudo did not use the same location for the LDAP
configuration files as the nss_ldap package. This has been fixed and sudo
now looks for these files in the same location as the nss_ldap package.
(BZ#652726)

* When a file was edited using the "sudo -e file" or the "sudoedit file"
command, the editor being executed for this task was logged only as
"sudoedit". With this update, the full path to the executable being used as
an editor is now logged (instead of "sudoedit"). (BZ#665131)

* A comment regarding the "visiblepw" option of the "Defaults" directive
has been added to the default "/etc/sudoers" file to clarify its usage.
(BZ#688640)

* This erratum upgrades sudo to upstream version 1.7.4p5, which provides a
number of bug fixes and enhancements over the previous version. (BZ#615087)

All users of sudo are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0010.html">CVE-2011-0010</cve>
                <bugzilla href="http://bugzilla.redhat.com/603823" id="603823">sudo - fix printing of entries with multiple host entries on a single line.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/615087" id="615087">Rebase sudo to version 1.7.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634159" id="634159">.pod files are packaged under /usr/share/doc/sudo*, and man page for sudoers.ldap is missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652726" id="652726">sudo and nss_ldap use different ldap.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668879" id="668879">CVE-2011-0010 sudo: does not ask for password on GID changes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688640" id="688640">Add comment about the visiblepw option into sudoers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110599005" comment="sudo is earlier than 0:1.7.4p5-5.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110599006" comment="sudo is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110600" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0600: dovecot security and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0600-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0600.html" />
          <reference source="CVE" ref_id="CVE-2010-3707" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3707.html" />
          <reference source="CVE" ref_id="CVE-2010-3780" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3780.html" />
    
    <description>Dovecot is an IMAP server for Linux, UNIX, and similar operating systems,
primarily written with security in mind.

A flaw was found in the way Dovecot handled SIGCHLD signals. If a large
amount of IMAP or POP3 session disconnects caused the Dovecot master
process to receive these signals rapidly, it could cause the master process
to crash. (CVE-2010-3780)

A flaw was found in the way Dovecot processed multiple Access Control Lists
(ACL) defined for a mailbox. In some cases, Dovecot could fail to apply the
more specific ACL entry, possibly resulting in more access being granted to
the user than intended. (CVE-2010-3707)

This update also adds the following enhancement:

* This erratum upgrades Dovecot to upstream version 2.0.9, providing
multiple fixes for the "dsync" utility and improving overall performance.
Refer to the "/usr/share/doc/dovecot-2.0.9/ChangeLog" file after installing
this update for further information about the changes. (BZ#637056)

Users of dovecot are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement. After installing the updated
packages, the dovecot service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3707.html">CVE-2010-3707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3780.html">CVE-2010-3780</cve>
                <bugzilla href="http://bugzilla.redhat.com/637056" id="637056">rebase dovecot to 2.0 final</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640410" id="640410">CVE-2010-3707 Dovecot: Failed to properly update ACL cache, when multiple rules defined rights for one subject</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/641276" id="641276">CVE-2010-3780 Dovecot: Busy master process, receiving a lot of SIGCHLD signals rapidly while logging, could die</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110600013" comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600014" comment="dovecot-pigeonhole is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110600009" comment="dovecot-mysql is earlier than 1:2.0.9-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600010" comment="dovecot-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110600005" comment="dovecot is earlier than 1:2.0.9-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600006" comment="dovecot is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110600011" comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600012" comment="dovecot-pgsql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110600007" comment="dovecot-devel is earlier than 1:2.0.9-2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600008" comment="dovecot-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110616" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0616: pidgin security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0616-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0616.html" />
          <reference source="CVE" ref_id="CVE-2011-1091" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1091.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Marius Wachtler as the original reporter.

This update also fixes the following bugs:

* Previous versions of the pidgin package did not properly clear certain
data structures used in libpurple/cipher.c when attempting to free them.
Partial information could potentially be extracted from the incorrectly
cleared regions of the previously freed memory. With this update, data
structures are properly cleared when freed. (BZ#684685)

* This erratum upgrades Pidgin to upstream version 2.7.9. For a list of all
changes addressed in this upgrade, refer to
http://developer.pidgin.im/wiki/ChangeLog (BZ#616917)

* Some incomplete translations for the kn_IN and ta_IN locales have been
corrected. (BZ#633860, BZ#640170)

Users of pidgin should upgrade to these updated packages, which resolve
these issues. Pidgin must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1091.html">CVE-2011-1091</cve>
                <bugzilla href="http://bugzilla.redhat.com/633860" id="633860">[kn_IN] Translation is not complete, untranslated message in Screenshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/640170" id="640170">[ta_IN] Translation need to review for "Add Account"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683031" id="683031">CVE-2011-1091 Pidgin: Multiple NULL pointer dereference flaws in Yahoo protocol plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684685" id="684685">Cipher API information disclosure in pidgin</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616021" comment="libpurple is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616022" comment="libpurple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616013" comment="libpurple-perl is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616014" comment="libpurple-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616009" comment="finch is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616010" comment="finch is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616005" comment="pidgin is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616006" comment="pidgin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616017" comment="pidgin-docs is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616018" comment="pidgin-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616023" comment="libpurple-devel is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616024" comment="libpurple-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616019" comment="finch-devel is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616020" comment="finch-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616015" comment="pidgin-perl is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616016" comment="pidgin-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616011" comment="pidgin-devel is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616012" comment="pidgin-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110616007" comment="libpurple-tcl is earlier than 0:2.7.9-3.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110616008" comment="libpurple-tcl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110677" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0677: openssl security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0677-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0677.html" />
          <reference source="CVE" ref_id="CVE-2011-0014" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0014.html" />
    
    <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

A buffer over-read flaw was discovered in the way OpenSSL parsed the
Certificate Status Request TLS extensions in ClientHello TLS handshake
messages. A remote attacker could possibly use this flaw to crash an SSL
server using the affected OpenSSL functionality. (CVE-2011-0014)

This update fixes the following bugs:

* The "openssl speed" command (which provides algorithm speed measurement)
failed when openssl was running in FIPS (Federal Information Processing
Standards) mode, even if testing of FIPS approved algorithms was requested.
FIPS mode disables ciphers and cryptographic hash algorithms that are not
approved by the NIST (National Institute of Standards and Technology)
standards. With this update, the "openssl speed" command no longer fails.
(BZ#619762)

* The "openssl pkcs12 -export" command failed to export a PKCS#12 file in
FIPS mode. The default algorithm for encrypting a certificate in the
PKCS#12 file was not FIPS approved and thus did not work. The command now
uses a FIPS approved algorithm by default in FIPS mode. (BZ#673453)

This update also adds the following enhancements:

* The "openssl s_server" command, which previously accepted connections
only over IPv4, now accepts connections over IPv6. (BZ#601612)

* For the purpose of allowing certain maintenance commands to be run (such
as "rsync"), an "OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW" environment variable
has been added. When a system is configured for FIPS mode and is in a
maintenance state, this newly added environment variable can be set to
allow software that requires the use of an MD5 cryptographic hash algorithm
to be run, even though the hash algorithm is not approved by the FIPS-140-2
standard. (BZ#673071)

Users of OpenSSL are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add these
enhancements. For the update to take effect, all services linked to the
OpenSSL library must be restarted, or the system rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0014.html">CVE-2011-0014</cve>
                <bugzilla href="http://bugzilla.redhat.com/601612" id="601612">s_server doesn't listen for ipv6 connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/619762" id="619762">openssl speed cmd fails on FIPS enabled machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676063" id="676063">CVE-2011-0014 openssl: OCSP stapling vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110677005" comment="openssl is earlier than 0:1.0.0-10.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677006" comment="openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110677011" comment="openssl-static is earlier than 0:1.0.0-10.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677012" comment="openssl-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110677009" comment="openssl-perl is earlier than 0:1.0.0-10.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677010" comment="openssl-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110677007" comment="openssl-devel is earlier than 0:1.0.0-10.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677008" comment="openssl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110779" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0779: avahi security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0779-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0779.html" />
          <reference source="CVE" ref_id="CVE-2011-1002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1002.html" />
    
    <description>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zero Configuration Networking. It facilitates service
discovery on a local network. Avahi and Avahi-aware applications allow you
to plug your computer into a network and, with no configuration, view other
people to chat with, view printers to print to, and find shared files on
other computers.

A flaw was found in the way the Avahi daemon (avahi-daemon) processed
Multicast DNS (mDNS) packets with an empty payload. An attacker on the
local network could use this flaw to cause avahi-daemon on a target system
to enter an infinite loop via an empty mDNS UDP packet. (CVE-2011-1002)

This update also fixes the following bug:

* Previously, the avahi packages in Red Hat Enterprise Linux 6 were not
compiled with standard RPM CFLAGS; therefore, the Stack Protector and
Fortify Source protections were not enabled, and the debuginfo packages did
not contain the information required for debugging. This update corrects
this issue by using proper CFLAGS when compiling the packages. (BZ#629954,
BZ#684276)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the update,
avahi-daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1002.html">CVE-2011-1002</cve>
                <bugzilla href="http://bugzilla.redhat.com/667187" id="667187">CVE-2011-1002 avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684276" id="684276">[PATCH] avahi debuginfo useless</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779043" comment="avahi-qt4-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779044" comment="avahi-qt4-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779027" comment="avahi-compat-howl is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779028" comment="avahi-compat-howl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779013" comment="avahi-dnsconfd is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779014" comment="avahi-dnsconfd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779029" comment="avahi-glib-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779030" comment="avahi-glib-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779017" comment="avahi-ui is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779018" comment="avahi-ui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779005" comment="avahi is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779006" comment="avahi is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779021" comment="avahi-libs is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779022" comment="avahi-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779007" comment="avahi-autoipd is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779008" comment="avahi-autoipd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779023" comment="avahi-compat-howl-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779024" comment="avahi-compat-howl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779033" comment="avahi-compat-libdns_sd is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779034" comment="avahi-compat-libdns_sd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779031" comment="avahi-ui-tools is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779032" comment="avahi-ui-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779025" comment="avahi-ui-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779026" comment="avahi-ui-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779015" comment="avahi-glib is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779016" comment="avahi-glib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779039" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779040" comment="avahi-compat-libdns_sd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779037" comment="avahi-tools is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779038" comment="avahi-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779035" comment="avahi-qt3 is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779036" comment="avahi-qt3 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779011" comment="avahi-qt3-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779012" comment="avahi-qt3-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779045" comment="avahi-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779046" comment="avahi-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779041" comment="avahi-gobject is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779042" comment="avahi-gobject is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779019" comment="avahi-gobject-devel is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779020" comment="avahi-gobject-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110779009" comment="avahi-qt4 is earlier than 0:0.6.25-11.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110779010" comment="avahi-qt4 is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110791" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0791: tomcat6 security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0791-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0791.html" />
          <reference source="CVE" ref_id="CVE-2010-3718" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3718.html" />
          <reference source="CVE" ref_id="CVE-2010-4172" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4172.html" />
          <reference source="CVE" ref_id="CVE-2011-0013" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0013.html" />
    
    <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that web applications could modify the location of the Tomcat
host's work directory. As web applications deployed on Tomcat have read and
write access to this directory, a malicious web application could use this
flaw to trick Tomcat into giving it read and write access to an arbitrary
directory on the file system. (CVE-2010-3718)

A cross-site scripting (XSS) flaw was found in the Manager application,
used for managing web applications on Tomcat. If a remote attacker could
trick a user who is logged into the Manager application into visiting a
specially-crafted URL, the attacker could perform Manager application tasks
with the privileges of the logged in user. (CVE-2010-4172)

A second cross-site scripting (XSS) flaw was found in the Manager
application. A malicious web application could use this flaw to conduct an
XSS attack, leading to arbitrary web script execution with the privileges
of victims who are logged into and viewing Manager application web pages.
(CVE-2011-0013)

This update also fixes the following bugs:

* A bug in the "tomcat6" init script prevented additional Tomcat instances
from starting. As well, running "service tomcat6 start" caused
configuration options applied from "/etc/sysconfig/tomcat6" to be
overwritten with those from "/etc/tomcat6/tomcat6.conf". With this update,
multiple instances of Tomcat run as expected. (BZ#636997)

* The "/usr/share/java/" directory was missing a symbolic link to the
"/usr/share/tomcat6/bin/tomcat-juli.jar" library. Because this library was
mandatory for certain operations (such as running the Jasper JSP
precompiler), the "build-jar-repository" command was unable to compose a
valid classpath. With this update, the missing symbolic link has been
added. (BZ#661244)

* Previously, the "tomcat6" init script failed to start Tomcat with a "This
account is currently not available." message when Tomcat was configured to
run under a user that did not have a valid shell configured as a login
shell. This update modifies the init script to work correctly regardless of
the daemon user's login shell. Additionally, these new tomcat6 packages now
set "/sbin/nologin" as the login shell for the "tomcat" user upon
installation, as recommended by deployment best practices. (BZ#678671)

* Some standard Tomcat directories were missing write permissions for the
"tomcat" group, which could cause certain applications to fail with errors
such as "No output folder". This update adds write permissions for the
"tomcat" group to the affected directories. (BZ#643809)

* The "/usr/sbin/tomcat6" wrapper script used a hard-coded path to the
"catalina.out" file, which may have caused problems (such as for logging
init script output) if Tomcat was being run with a user other than "tomcat"
and with CATALINA_BASE set to a directory other than the default.
(BZ#695284, BZ#697504)

* Stopping Tomcat could have resulted in traceback errors being logged to
"catalina.out" when certain web applications were deployed. (BZ#698624)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-19" />
        <updated date="2011-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3718.html">CVE-2010-3718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4172.html">CVE-2010-4172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0013.html">CVE-2011-0013</cve>
                <bugzilla href="http://bugzilla.redhat.com/636997" id="636997">Additionally Created Instances of Tomcat  are broken / don't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643809" id="643809">Bad permissions on tomcat folders</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656246" id="656246">CVE-2010-4172 tomcat: cross-site-scripting vulnerability in the manager application</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661244" id="661244">Missing tomcat6-juli link in /usr/share/java</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675786" id="675786">CVE-2011-0013 tomcat: XSS vulnerability in HTML Manager interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675792" id="675792">CVE-2010-3718 tomcat: file permission bypass flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678671" id="678671">tomcat user requires login shell</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695284" id="695284">catalina.out path hard-coded in /usr/sbin/tomcat6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697504" id="697504">tomcat6-6.0.wrapper redirects init script output to wrong place</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791005" comment="tomcat6 is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335006" comment="tomcat6 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791007" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335024" comment="tomcat6-el-2.1-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791013" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335022" comment="tomcat6-admin-webapps is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791019" comment="tomcat6-webapps is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335014" comment="tomcat6-webapps is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791015" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335020" comment="tomcat6-docs-webapp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791021" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335008" comment="tomcat6-jsp-2.1-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791009" comment="tomcat6-javadoc is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335012" comment="tomcat6-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791011" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335010" comment="tomcat6-servlet-2.5-api is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110791017" comment="tomcat6-lib is earlier than 0:6.0.24-33.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110335018" comment="tomcat6-lib is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110833" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0833: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0833-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0833.html" />
          <reference source="CVE" ref_id="CVE-2011-0726" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0726.html" />
          <reference source="CVE" ref_id="CVE-2011-1078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1078.html" />
          <reference source="CVE" ref_id="CVE-2011-1079" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1079.html" />
          <reference source="CVE" ref_id="CVE-2011-1080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1080.html" />
          <reference source="CVE" ref_id="CVE-2011-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1093.html" />
          <reference source="CVE" ref_id="CVE-2011-1163" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1163.html" />
          <reference source="CVE" ref_id="CVE-2011-1166" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1166.html" />
          <reference source="CVE" ref_id="CVE-2011-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1170.html" />
          <reference source="CVE" ref_id="CVE-2011-1171" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1171.html" />
          <reference source="CVE" ref_id="CVE-2011-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1172.html" />
          <reference source="CVE" ref_id="CVE-2011-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1494.html" />
          <reference source="CVE" ref_id="CVE-2011-1495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1495.html" />
          <reference source="CVE" ref_id="CVE-2011-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1577.html" />
          <reference source="CVE" ref_id="CVE-2011-1763" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1763.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw in the dccp_rcv_state_process() function could allow a remote
attacker to cause a denial of service, even when the socket was already
closed. (CVE-2011-1093, Important)

* Multiple buffer overflow flaws were found in the Linux kernel's
Management Module Support for Message Passing Technology (MPT) based
controllers. A local, unprivileged user could use these flaws to cause a
denial of service, an information leak, or escalate their privileges.
(CVE-2011-1494, CVE-2011-1495, Important)

* A missing validation of a null-terminated string data structure element
in the bnep_sock_ioctl() function could allow a local user to cause an
information leak or a denial of service. (CVE-2011-1079, Moderate)

* Missing error checking in the way page tables were handled in the Xen
hypervisor implementation could allow a privileged guest user to cause the
host, and the guests, to lock up. (CVE-2011-1166, Moderate)

* A flaw was found in the way the Xen hypervisor implementation checked for
the upper boundary when getting a new event channel port. A privileged
guest user could use this flaw to cause a denial of service or escalate
their privileges. (CVE-2011-1763, Moderate)

* The start_code and end_code values in "/proc/[pid]/stat" were not
protected. In certain scenarios, this flaw could be used to defeat Address
Space Layout Randomization (ASLR). (CVE-2011-0726, Low)

* A missing initialization flaw in the sco_sock_getsockopt() function could
allow a local, unprivileged user to cause an information leak.
(CVE-2011-1078, Low)

* A missing validation of a null-terminated string data structure element
in the do_replace() function could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1080, Low)

* A buffer overflow flaw in the DEC Alpha OSF partition implementation in
the Linux kernel could allow a local attacker to cause an information leak
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1163, Low)

* Missing validations of null-terminated string data structure elements in
the do_replace(), compat_do_replace(), do_ipt_get_ctl(), do_ip6t_get_ctl(),
and do_arpt_get_ctl() functions could allow a local user who has the
CAP_NET_ADMIN capability to cause an information leak. (CVE-2011-1170,
CVE-2011-1171, CVE-2011-1172, Low)

* A heap overflow flaw in the Linux kernel's EFI GUID Partition Table (GPT)
implementation could allow a local attacker to cause a denial of service
by mounting a disk that contains specially-crafted partition tables.
(CVE-2011-1577, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1494 and
CVE-2011-1495; Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1078,
CVE-2011-1080, CVE-2011-1170, CVE-2011-1171, and CVE-2011-1172; Kees Cook
for reporting CVE-2011-0726; and Timo Warns for reporting CVE-2011-1163
and CVE-2011-1577.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0726.html">CVE-2011-0726</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1078.html">CVE-2011-1078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1079.html">CVE-2011-1079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1080.html">CVE-2011-1080</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1093.html">CVE-2011-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1163.html">CVE-2011-1163</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1166.html">CVE-2011-1166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1170.html">CVE-2011-1170</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1171.html">CVE-2011-1171</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1172.html">CVE-2011-1172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1494.html">CVE-2011-1494</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1495.html">CVE-2011-1495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1577.html">CVE-2011-1577</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1763.html">CVE-2011-1763</cve>
                <bugzilla href="http://bugzilla.redhat.com/681259" id="681259">CVE-2011-1078 kernel: bt sco_conninfo infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681260" id="681260">CVE-2011-1079 kernel: bnep device field missing NULL terminator</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681262" id="681262">CVE-2011-1080 kernel: ebtables stack infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682954" id="682954">CVE-2011-1093 kernel: dccp: fix oops on Reset after close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684569" id="684569">CVE-2011-0726 kernel: proc: protect mm start_code/end_code in /proc/pid/stat</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688021" id="688021">CVE-2011-1163 kernel: fs/partitions: Corrupted OSF partition table infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688156" id="688156">[5.6][REG]for some uses of 'nfsservctl' system call, the kernel crashes. [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688579" id="688579">CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689321" id="689321">CVE-2011-1170 ipv4: netfilter: arp_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689327" id="689327">CVE-2011-1171 ipv4: netfilter: ip_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689345" id="689345">CVE-2011-1172 ipv6: netfilter: ip6_tables: fix infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689699" id="689699">Deadlock between device driver attachment and device removal with a USB device [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689700" id="689700">[NetApp 5.6 Bug] QLogic 8G FC firmware dumps seen during IO [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690134" id="690134">Time runs too fast in a VM on processors with > 4GHZ freq [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690239" id="690239">gfs2: creating large files suddenly slow to a crawl [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694021" id="694021">CVE-2011-1494 CVE-2011-1495 kernel: drivers/scsi/mpt2sas: prevent heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695976" id="695976">CVE-2011-1577 kernel: corrupted GUID partition tables can cause kernel oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696136" id="696136">RHEL 5.6 (kernel -238) causes audio issues [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697448" id="697448">slab corruption after seeing some nfs-related BUG: warning [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/699808" id="699808">dasd: fix race between open and offline [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/701240" id="701240">CVE-2011-1763 kernel: xen: improper upper boundary check in get_free_port() function</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833004" comment="kernel-headers is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833002" comment="kernel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833024" comment="kernel-doc is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833020" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833006" comment="kernel-devel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833008" comment="kernel-debug is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833016" comment="kernel-kdump is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833014" comment="kernel-xen-devel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833010" comment="kernel-debug-devel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833022" comment="kernel-PAE is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833018" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110833012" comment="kernel-xen is earlier than 0:2.6.18-238.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110836" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0836: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0836-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0836.html" />
          <reference source="CVE" ref_id="CVE-2010-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3858.html" />
          <reference source="CVE" ref_id="CVE-2011-1598" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1598.html" />
          <reference source="CVE" ref_id="CVE-2011-1748" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1748.html" />
          <reference source="CVE" ref_id="CVE-2011-1770" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1770.html" />
          <reference source="CVE" ref_id="CVE-2011-1771" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1771.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer underflow flaw, leading to a buffer overflow, was found in the
Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
This could allow a remote attacker to cause a denial of service.
(CVE-2011-1770, Important)

* Missing sanity checks were found in setup_arg_pages() in the Linux
kernel. When making the size of the argument and environment area on the
stack very large, it could trigger a BUG_ON(), resulting in a local denial
of service. (CVE-2010-3858, Moderate)

* A missing validation check was found in the bcm_release() and
raw_release() functions in the Linux kernel's Controller Area Network (CAN)
implementation. This could allow a local, unprivileged user to cause a
denial of service. (CVE-2011-1598, CVE-2011-1748, Moderate)

* The fix for Red Hat Bugzilla bug 656461, as provided in RHSA-2011:0542,
introduced a regression in the cifs_close() function in the Linux kernel's
Common Internet File System (CIFS) implementation. A local, unprivileged
user with write access to a CIFS file system could use this flaw to cause a
denial of service. (CVE-2011-1771, Moderate)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1770; Brad
Spengler for reporting CVE-2010-3858; and Oliver Hartkopp for reporting
CVE-2011-1748.

This update also fixes various bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-01" />
        <updated date="2011-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3858.html">CVE-2010-3858</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1598.html">CVE-2011-1598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1748.html">CVE-2011-1748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1770.html">CVE-2011-1770</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1771.html">CVE-2011-1771</cve>
                <bugzilla href="http://bugzilla.redhat.com/645222" id="645222">CVE-2010-3858 kernel: setup_arg_pages: diagnose excessive argument size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698057" id="698057">CVE-2011-1598 CVE-2011-1748 kernel: missing check in can/bcm and can/raw socket releases</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703011" id="703011">CVE-2011-1770 kernel: dccp: handle invalid feature options length</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703016" id="703016">CVE-2011-1771 kernel: cifs oops when creating file with O_DIRECT set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/704014" id="704014">[brocade 6.1 bug] bfa fc staying tech preview [rhel-6.1.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836023" comment="kernel-firmware is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836007" comment="kernel-headers is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836005" comment="kernel is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836025" comment="kernel-doc is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836017" comment="kernel-devel is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836013" comment="perf is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836015" comment="kernel-debug is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836021" comment="kernel-kdump is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836011" comment="kernel-debug-devel is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836019" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110836009" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.2.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110837" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0837: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0837-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0837.html" />
          <reference source="CVE" ref_id="CVE-2009-1570" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1570.html" />
          <reference source="CVE" ref_id="CVE-2010-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4541.html" />
          <reference source="CVE" ref_id="CVE-2010-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4543.html" />
          <reference source="CVE" ref_id="CVE-2011-1178" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1178.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's Microsoft Windows Bitmap (BMP) and Personal Computer
eXchange (PCX) image file plug-ins. An attacker could create a
specially-crafted BMP or PCX image file that, when opened, could cause the
relevant plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2009-1570, CVE-2011-1178)

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Sphere Designer
image filter. An attacker could create a specially-crafted Sphere Designer
filter configuration file that, when opened, could cause the Sphere
Designer plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2010-4541)

Red Hat would like to thank Stefan Cornelius of Secunia Research for
responsibly reporting the CVE-2009-1570 flaw.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1570.html">CVE-2009-1570</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4541.html">CVE-2010-4541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4543.html">CVE-2010-4543</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1178.html">CVE-2011-1178</cve>
                <bugzilla href="http://bugzilla.redhat.com/537356" id="537356">CVE-2009-1570 Gimp: Integer overflow in the BMP image file plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689831" id="689831">CVE-2011-1178 Gimp: Integer overflow in the PCX image file plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703403" id="703403">CVE-2010-4541 Gimp: Stack-based buffer overflow in SphereDesigner plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703407" id="703407">CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110837004" comment="gimp-devel is earlier than 1:2.0.5-7.0.7.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110837005" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110837002" comment="gimp is earlier than 1:2.0.5-7.0.7.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110837003" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110838" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0838: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0838-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0838.html" />
          <reference source="CVE" ref_id="CVE-2009-1570" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1570.html" />
          <reference source="CVE" ref_id="CVE-2010-4540" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4540.html" />
          <reference source="CVE" ref_id="CVE-2010-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4541.html" />
          <reference source="CVE" ref_id="CVE-2010-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4542.html" />
          <reference source="CVE" ref_id="CVE-2010-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4543.html" />
          <reference source="CVE" ref_id="CVE-2011-1178" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1178.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's Microsoft Windows Bitmap (BMP) and Personal Computer
eXchange (PCX) image file plug-ins. An attacker could create a
specially-crafted BMP or PCX image file that, when opened, could cause the
relevant plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. (CVE-2009-1570, CVE-2011-1178)

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Lightning,
Sphere Designer, and Gfig image filters. An attacker could create a
specially-crafted Lightning, Sphere Designer, or Gfig filter configuration
file that, when opened, could cause the relevant plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)

Red Hat would like to thank Stefan Cornelius of Secunia Research for
responsibly reporting the CVE-2009-1570 flaw.

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1570.html">CVE-2009-1570</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4540.html">CVE-2010-4540</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4541.html">CVE-2010-4541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4542.html">CVE-2010-4542</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4543.html">CVE-2010-4543</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1178.html">CVE-2011-1178</cve>
                <bugzilla href="http://bugzilla.redhat.com/537356" id="537356">CVE-2009-1570 Gimp: Integer overflow in the BMP image file plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666793" id="666793">CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689831" id="689831">CVE-2011-1178 Gimp: Integer overflow in the PCX image file plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703403" id="703403">CVE-2010-4541 Gimp: Stack-based buffer overflow in SphereDesigner plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703405" id="703405">CVE-2010-4542 Gimp: Stack-based buffer overflow in Gfig plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703407" id="703407">CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110838006" comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110838007" comment="gimp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110838004" comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110838005" comment="gimp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110838002" comment="gimp is earlier than 2:2.2.13-2.0.7.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110838003" comment="gimp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110839" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0839: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0839.html" />
          <reference source="CVE" ref_id="CVE-2010-4540" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4540.html" />
          <reference source="CVE" ref_id="CVE-2010-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4541.html" />
          <reference source="CVE" ref_id="CVE-2010-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4542.html" />
          <reference source="CVE" ref_id="CVE-2010-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4543.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted PSP
image file that, when opened, could cause the PSP plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Lightning,
Sphere Designer, and Gfig image filters. An attacker could create a
specially-crafted Lightning, Sphere Designer, or Gfig filter configuration
file that, when opened, could cause the relevant plug-in to crash or,
potentially, execute arbitrary code with the privileges of the user running
the GIMP. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)

Users of the GIMP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The GIMP must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4540.html">CVE-2010-4540</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4541.html">CVE-2010-4541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4542.html">CVE-2010-4542</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4543.html">CVE-2010-4543</cve>
                <bugzilla href="http://bugzilla.redhat.com/666793" id="666793">CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703403" id="703403">CVE-2010-4541 Gimp: Stack-based buffer overflow in SphereDesigner plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703405" id="703405">CVE-2010-4542 Gimp: Stack-based buffer overflow in Gfig plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703407" id="703407">CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110839009" comment="gimp-libs is earlier than 2:2.6.9-4.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110839010" comment="gimp-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110839007" comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110839008" comment="gimp-help-browser is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110839011" comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110839012" comment="gimp-devel-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110839013" comment="gimp-devel is earlier than 2:2.6.9-4.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110839014" comment="gimp-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110839005" comment="gimp is earlier than 2:2.6.9-4.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110839006" comment="gimp is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110841" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0841: systemtap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0841-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0841.html" />
          <reference source="CVE" ref_id="CVE-2011-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1769.html" />
    
    <description>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

A divide-by-zero flaw was found in the way SystemTap handled malformed
debugging information in DWARF format. When SystemTap unprivileged mode was
enabled, an unprivileged user in the stapusr group could use this flaw to
crash the system. Additionally, a privileged user (root, or a member of the
stapdev group) could trigger this flaw when tricked into instrumenting a
specially-crafted ELF binary, even when unprivileged mode was not enabled.
(CVE-2011-1769)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1769.html">CVE-2011-1769</cve>
                <bugzilla href="http://bugzilla.redhat.com/702687" id="702687">CVE-2011-1769 systemtap: does not guard against DWARF operations div-by-zero errors, which can cause a kernel panic</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841010" comment="systemtap-testsuite is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841011" comment="systemtap-testsuite is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841006" comment="systemtap-runtime is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841007" comment="systemtap-runtime is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841002" comment="systemtap is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841003" comment="systemtap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841008" comment="systemtap-sdt-devel is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841009" comment="systemtap-sdt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841012" comment="systemtap-client is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841013" comment="systemtap-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841004" comment="systemtap-initscript is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841005" comment="systemtap-initscript is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110841014" comment="systemtap-server is earlier than 0:1.3-4.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841015" comment="systemtap-server is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110842" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0842: systemtap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0842-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0842.html" />
          <reference source="CVE" ref_id="CVE-2011-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1769.html" />
          <reference source="CVE" ref_id="CVE-2011-1781" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1781.html" />
    
    <description>SystemTap is an instrumentation system for systems running the Linux
kernel, version 2.6. Developers can write scripts to collect data on the
operation of the system.

Two divide-by-zero flaws were found in the way SystemTap handled malformed
debugging information in DWARF format. When SystemTap unprivileged mode was
enabled, an unprivileged user in the stapusr group could use these flaws to
crash the system. Additionally, a privileged user (root, or a member of the
stapdev group) could trigger these flaws when tricked into instrumenting a
specially-crafted ELF binary, even when unprivileged mode was not enabled.
(CVE-2011-1769, CVE-2011-1781)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1769.html">CVE-2011-1769</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1781.html">CVE-2011-1781</cve>
                <bugzilla href="http://bugzilla.redhat.com/702687" id="702687">CVE-2011-1769 systemtap: does not guard against DWARF operations div-by-zero errors, which can cause a kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703972" id="703972">CVE-2011-1781 systemtap: divide by zero stack unwinding flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842019" comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842020" comment="systemtap-runtime is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842017" comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842018" comment="systemtap-testsuite is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842009" comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842010" comment="systemtap-grapher is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842005" comment="systemtap is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842006" comment="systemtap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842007" comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842008" comment="systemtap-sdt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842015" comment="systemtap-client is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842016" comment="systemtap-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842013" comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842014" comment="systemtap-initscript is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110842011" comment="systemtap-server is earlier than 0:1.4-6.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842012" comment="systemtap-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110843" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0843: postfix security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0843-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0843.html" />
          <reference source="CVE" ref_id="CVE-2011-1720" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1720.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A heap-based buffer over-read flaw was found in the way Postfix performed
SASL handlers management for SMTP sessions, when Cyrus SASL authentication
was enabled. A remote attacker could use this flaw to cause the Postfix
smtpd server to crash via a specially-crafted SASL authentication request.
The smtpd process was automatically restarted by the postfix master process
after the time configured with service_throttle_time elapsed.
(CVE-2011-1720)

Note: Cyrus SASL authentication for Postfix is not enabled by default.

Red Hat would like to thank the CERT/CC for reporting this issue. Upstream
acknowledges Thomas Jarosch of Intra2net AG as the original reporter.

Users of Postfix are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the postfix service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1720.html">CVE-2011-1720</cve>
                <bugzilla href="http://bugzilla.redhat.com/699035" id="699035">CVE-2011-1720 postfix (smtpd): Crash due to improper management of SASL handlers for SMTP sessions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843004" comment="postfix-pflogsumm is earlier than 2:2.3.3-2.3.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422005" comment="postfix-pflogsumm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843002" comment="postfix is earlier than 2:2.3.3-2.3.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422003" comment="postfix is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843009" comment="postfix-pflogsumm is earlier than 2:2.2.10-1.5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422010" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843007" comment="postfix is earlier than 2:2.2.10-1.5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110422008" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843017" comment="postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110423008" comment="postfix-perl-scripts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110843015" comment="postfix is earlier than 2:2.6.6-2.2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110423006" comment="postfix is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110844" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0844: apr security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0844-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0844.html" />
          <reference source="CVE" ref_id="CVE-2011-1928" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1928.html" />
    
    <description>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It provides a free library of C data
structures and routines.

The fix for CVE-2011-0419 (released via RHSA-2011:0507) introduced an
infinite loop flaw in the apr_fnmatch() function when the APR_FNM_PATHNAME
matching flag was used. A remote attacker could possibly use this flaw to
cause a denial of service on an application using the apr_fnmatch()
function. (CVE-2011-1928)

Note: This problem affected httpd configurations using the "Location"
directive with wildcard URLs. The denial of service could have been
triggered during normal operation; it did not specifically require a
malicious HTTP request.

This update also addresses additional problems introduced by the rewrite of
the apr_fnmatch() function, which was necessary to address the
CVE-2011-0419 flaw.

All apr users should upgrade to these updated packages, which contain a
backported patch to correct this issue. Applications using the apr library,
such as httpd, must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1928.html">CVE-2011-1928</cve>
                <bugzilla href="http://bugzilla.redhat.com/706203" id="706203">CVE-2011-1928 apr: DoS flaw in apr_fnmatch() due to fix for CVE-2011-0419</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844004" comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507005" comment="apr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844002" comment="apr is earlier than 0:1.2.7-11.el5_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507003" comment="apr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844006" comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507007" comment="apr-docs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844011" comment="apr-devel is earlier than 0:0.9.4-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507020" comment="apr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844009" comment="apr is earlier than 0:0.9.4-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507018" comment="apr is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844019" comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507015" comment="apr-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110844017" comment="apr is earlier than 0:1.3.9-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110507013" comment="apr is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110845" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0845: bind security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0845-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0845.html" />
          <reference source="CVE" ref_id="CVE-2011-1910" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1910.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

An off-by-one flaw was found in the way BIND processed negative responses
with large resource record sets (RRSets). An attacker able to send
recursive queries to a BIND server that is configured as a caching
resolver could use this flaw to cause named to exit with an assertion
failure. (CVE-2011-1910)

All BIND users are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-05-31" />
        <updated date="2011-05-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1910.html">CVE-2011-1910</cve>
                <bugzilla href="http://bugzilla.redhat.com/708301" id="708301">CVE-2011-1910 bind: Large RRSIG RRsets and Negative Caching can crash named</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845008" comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845009" comment="bind97-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845004" comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845005" comment="bind97-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845010" comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845011" comment="bind97-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845002" comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845003" comment="bind97 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845006" comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845007" comment="bind97-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845026" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845027" comment="bind-chroot is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845020" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845021" comment="bind-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845018" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845019" comment="bind-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845022" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845023" comment="bind-sdb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845016" comment="bind is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845017" comment="bind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110845024" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845025" comment="bind-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110850" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0850: flash-plugin security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0850-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0850.html" />
          <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This 
vulnerability is detailed on the Adobe security page APSB11-13, listed in 
the References section. (CVE-2011-2107)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.181.22</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-06" />
        <updated date="2011-06-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2107.html">CVE-2011-2107</cve>
                <bugzilla href="http://bugzilla.redhat.com/710981" id="710981">CVE-2011-2107 flash-plugin: Cross-site scripting vulnerability (APSB11-13)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110850002" comment="flash-plugin is earlier than 0:10.3.181.22-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110850008" comment="flash-plugin is earlier than 0:10.3.181.22-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110856" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0856: java-1.6.0-openjdk security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0856-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0856.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html" />
          <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Integer overflow flaws were found in the way Java2D parsed JPEG images and
user-supplied fonts. An attacker could use these flaws to execute arbitrary
code with the privileges of the user running an untrusted applet or
application. (CVE-2011-0862)

It was found that the MediaTracker implementation created Component
instances with unnecessary access privileges. A remote attacker could use
this flaw to elevate their privileges by utilizing an untrusted applet or
application that uses Swing. (CVE-2011-0871)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), resulting in an applet or application crashing. (CVE-2011-0864)

An information leak flaw was found in the NetworkInterface class. An
untrusted applet or application could use this flaw to access information
about available network interfaces that should only be available to
privileged code. (CVE-2011-0867)

An incorrect float-to-long conversion, leading to an overflow, was found
in the way certain objects (such as images and text) were transformed in
Java2D. A remote attacker could use this flaw to crash an untrusted applet
or application that uses Java2D. (CVE-2011-0868)

It was found that untrusted applets and applications could misuse a SOAP
connection to incorrectly set global HTTP proxy settings instead of
setting them in a local scope. This flaw could be used to intercept HTTP
requests. (CVE-2011-0869)

A flaw was found in the way signed objects were deserialized. If trusted
and untrusted code were running in the same Java Virtual Machine (JVM), and
both were deserializing the same signed object, the untrusted code could
modify said object by using this flaw to bypass the validation checks on
signed objects. (CVE-2011-0865)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0864.html">CVE-2011-0864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0868.html">CVE-2011-0868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0869.html">CVE-2011-0869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
                <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706234" id="706234">CVE-2011-0869 OpenJDK: unprivileged proxy settings change via SOAPConnection (SAAJ, 7013971)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706241" id="706241">CVE-2011-0868 OpenJDK: incorrect numeric type conversion in TransformHelper (2D, 7016495)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706245" id="706245">CVE-2011-0864 OpenJDK: JVM memory corruption via certain bytecode (HotSpot, 7020373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110856005" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214017" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110856011" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214019" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110856007" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214023" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110856013" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214021" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110856009" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214025" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110857" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0857: java-1.6.0-openjdk security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0857-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0857.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html" />
          <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Integer overflow flaws were found in the way Java2D parsed JPEG images and
user-supplied fonts. An attacker could use these flaws to execute arbitrary
code with the privileges of the user running an untrusted applet or
application. (CVE-2011-0862)

It was found that the MediaTracker implementation created Component
instances with unnecessary access privileges. A remote attacker could use
this flaw to elevate their privileges by utilizing an untrusted applet or
application that uses Swing. (CVE-2011-0871)

A flaw was found in the HotSpot component in OpenJDK. Certain bytecode
instructions confused the memory management within the Java Virtual Machine
(JVM), resulting in an applet or application crashing. (CVE-2011-0864)

An information leak flaw was found in the NetworkInterface class. An
untrusted applet or application could use this flaw to access information
about available network interfaces that should only be available to
privileged code. (CVE-2011-0867)

An incorrect float-to-long conversion, leading to an overflow, was found
in the way certain objects (such as images and text) were transformed in
Java2D. A remote attacker could use this flaw to crash an untrusted applet
or application that uses Java2D. (CVE-2011-0868)

It was found that untrusted applets and applications could misuse a SOAP
connection to incorrectly set global HTTP proxy settings instead of
setting them in a local scope. This flaw could be used to intercept HTTP
requests. (CVE-2011-0869)

A flaw was found in the way signed objects were deserialized. If trusted
and untrusted code were running in the same Java Virtual Machine (JVM), and
both were deserializing the same signed object, the untrusted code could
modify said object by using this flaw to bypass the validation checks on
signed objects. (CVE-2011-0865)

Note: All of the above flaws can only be remotely triggered in OpenJDK by
calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which provide OpenJDK 6 b20 / IcedTea 1.9.8 and resolve these
issues. All running instances of OpenJDK Java must be restarted for the
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0864.html">CVE-2011-0864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0868.html">CVE-2011-0868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0869.html">CVE-2011-0869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
                <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706234" id="706234">CVE-2011-0869 OpenJDK: unprivileged proxy settings change via SOAPConnection (SAAJ, 7013971)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706241" id="706241">CVE-2011-0868 OpenJDK: incorrect numeric type conversion in TransformHelper (2D, 7016495)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706245" id="706245">CVE-2011-0864 OpenJDK: JVM memory corruption via certain bytecode (HotSpot, 7020373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110857002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110857006" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176005" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110857004" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110857010" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176007" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110857008" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.22.1.9.8.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110858" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0858: xerces-j2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0858-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0858.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
    
    <description>The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.

A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. Applications using the Apache Xerces2 Java
Parser must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
                <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858013" comment="xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858014" comment="xerces-j2-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858017" comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858018" comment="xerces-j2-javadoc-xni is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858015" comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858016" comment="xerces-j2-javadoc-other is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858007" comment="xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858008" comment="xerces-j2-scripts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858011" comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858012" comment="xerces-j2-javadoc-impl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858009" comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858010" comment="xerces-j2-javadoc-apis is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110858005" comment="xerces-j2 is earlier than 0:2.7.1-12.6.el6_0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110858006" comment="xerces-j2 is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110859" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0859: cyrus-imapd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0859-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0859.html" />
          <reference source="CVE" ref_id="CVE-2011-1926" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1926.html" />
    
    <description>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

It was discovered that cyrus-imapd did not flush the received commands
buffer after switching to TLS encryption for IMAP, LMTP, NNTP, and POP3
sessions. A man-in-the-middle attacker could use this flaw to inject
protocol commands into a victim's TLS session initialization messages. This
could lead to those commands being processed by cyrus-imapd, potentially
allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-1926)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the update, cyrus-imapd will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1926.html">CVE-2011-1926</cve>
                <bugzilla href="http://bugzilla.redhat.com/705288" id="705288">CVE-2011-1926 cyrus-imapd: STARTTLS plaintext command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859004" comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859005" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859002" comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859003" comment="cyrus-imapd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859008" comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859009" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859006" comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859007" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859021" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859022" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859019" comment="cyrus-imapd-murder is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859020" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859011" comment="cyrus-imapd is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859012" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859015" comment="cyrus-imapd-devel is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859016" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859013" comment="cyrus-imapd-utils is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859014" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859017" comment="perl-Cyrus is earlier than 0:2.2.12-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859018" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859027" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859028" comment="cyrus-imapd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859031" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859032" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110859029" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859030" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110860" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0860: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0860-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0860.html" />
          <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html" />
          <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html" />
          <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html" />
          <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
          <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html" />
    
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. Further
information about these flaws can be found on the "Oracle Java SE Critical
Patch Update Advisory" page, listed in the References section.
(CVE-2011-0802, CVE-2011-0814, CVE-2011-0862, CVE-2011-0863, CVE-2011-0864,
CVE-2011-0865, CVE-2011-0867, CVE-2011-0868, CVE-2011-0869, CVE-2011-0871,
CVE-2011-0873)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide JDK and JRE 6 Update 26 and resolve these issues.
All running instances of Sun Java must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0802.html">CVE-2011-0802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0814.html">CVE-2011-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0863.html">CVE-2011-0863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0864.html">CVE-2011-0864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0868.html">CVE-2011-0868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0869.html">CVE-2011-0869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0873.html">CVE-2011-0873</cve>
                <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706234" id="706234">CVE-2011-0869 OpenJDK: unprivileged proxy settings change via SOAPConnection (SAAJ, 7013971)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706241" id="706241">CVE-2011-0868 OpenJDK: incorrect numeric type conversion in TransformHelper (2D, 7016495)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706245" id="706245">CVE-2011-0864 OpenJDK: JVM memory corruption via certain bytecode (HotSpot, 7020373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711675" id="711675">CVE-2011-0873 Oracle/IBM JDK: unspecified vulnerability fixed in 6u26 (2D)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711676" id="711676">CVE-2011-0863 Oracle/IBM JDK: unspecified vulnerability fixed in 6u26 (Deployment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711677" id="711677">CVE-2011-0802 CVE-2011-0814 Oracle/IBM JDK: unspecified vulnerabilities fixed in 6u26 (Sound)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860006" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282009" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860002" comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860008" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282013" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860010" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282007" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860004" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282011" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860012" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282005" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860026" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282025" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860018" comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282019" comment="java-1.6.0-sun is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860024" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282029" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860028" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282027" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860020" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282023" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110860022" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282021" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110861" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0861: subversion security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0861-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0861.html" />
          <reference source="CVE" ref_id="CVE-2011-1752" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1752.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed requests submitted against the URL of a baselined resource. A
malicious, remote user could use this flaw to cause the httpd process
serving the request to crash. (CVE-2011-1752)

Red Hat would like to thank the Apache Subversion project for reporting
this issue. Upstream acknowledges Joe Schaefer of the Apache Software
Foundation as the original reporter.

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1752.html">CVE-2011-1752</cve>
                <bugzilla href="http://bugzilla.redhat.com/709111" id="709111">CVE-2011-1752 subversion (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110861004" comment="subversion-devel is earlier than 0:1.1.4-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110861005" comment="subversion-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110861002" comment="subversion is earlier than 0:1.1.4-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110861003" comment="subversion is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110861008" comment="subversion-perl is earlier than 0:1.1.4-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110861009" comment="subversion-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110861006" comment="mod_dav_svn is earlier than 0:1.1.4-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110861007" comment="mod_dav_svn is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110862" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0862: subversion security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0862-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-1752" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1752.html" />
          <reference source="CVE" ref_id="CVE-2011-1783" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1783.html" />
          <reference source="CVE" ref_id="CVE-2011-1921" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1921.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

An infinite loop flaw was found in the way the mod_dav_svn module processed
certain data sets. If the SVNPathAuthz directive was set to
"short_circuit", and path-based access control for files and directories
was enabled, a malicious, remote user could use this flaw to cause the
httpd process serving the request to consume an excessive amount of system
memory. (CVE-2011-1783)

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
processed requests submitted against the URL of a baselined resource. A
malicious, remote user could use this flaw to cause the httpd process
serving the request to crash. (CVE-2011-1752)

An information disclosure flaw was found in the way the mod_dav_svn
module processed certain URLs when path-based access control for files and
directories was enabled. A malicious, remote user could possibly use this
flaw to access certain files in a repository that would otherwise not be
accessible to them. Note: This vulnerability cannot be triggered if the
SVNPathAuthz directive is set to "short_circuit". (CVE-2011-1921)

Red Hat would like to thank the Apache Subversion project for reporting
these issues. Upstream acknowledges Joe Schaefer of the Apache Software
Foundation as the original reporter of CVE-2011-1752; Ivan Zhakov of
VisualSVN as the original reporter of CVE-2011-1783; and Kamesh
Jayachandran of CollabNet, Inc. as the original reporter of CVE-2011-1921.

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-08" />
        <updated date="2011-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1752.html">CVE-2011-1752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1783.html">CVE-2011-1783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1921.html">CVE-2011-1921</cve>
                <bugzilla href="http://bugzilla.redhat.com/709111" id="709111">CVE-2011-1752 subversion (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/709112" id="709112">CVE-2011-1783 subversion (mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/709114" id="709114">CVE-2011-1921 subversion (mod_dav_svn): File contents disclosure of files configured to be unreadable by those users</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862010" comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257007" comment="subversion-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862002" comment="subversion is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257003" comment="subversion is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862008" comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257013" comment="subversion-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862006" comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257009" comment="subversion-ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862012" comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257011" comment="subversion-javahl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862004" comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110257005" comment="mod_dav_svn is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862020" comment="subversion-devel is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258020" comment="subversion-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862024" comment="subversion-kde is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258010" comment="subversion-kde is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862018" comment="subversion is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258006" comment="subversion is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862030" comment="subversion-perl is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258016" comment="subversion-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862028" comment="subversion-gnome is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258018" comment="subversion-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862026" comment="subversion-ruby is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258008" comment="subversion-ruby is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862034" comment="subversion-javahl is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258022" comment="subversion-javahl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862022" comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258014" comment="mod_dav_svn is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110862032" comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110258012" comment="subversion-svn2cl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110869" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0869: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0869-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0869.html" />
          <reference source="CVE" ref_id="CVE-2011-2110" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2110.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed on the Adobe security page APSB11-18, listed in
the References section. Specially-crafted SWF content could cause
flash-plugin to crash or, potentially, execute arbitrary code.
(CVE-2011-2110)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.181.26.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-15" />
        <updated date="2011-06-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2110.html">CVE-2011-2110</cve>
                <bugzilla href="http://bugzilla.redhat.com/713308" id="713308">CVE-2011-2110 flash-plugin: memory corruption can lead to arbitrary code execution (APSB11-18)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110869002" comment="flash-plugin is earlier than 0:10.3.181.26-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110869008" comment="flash-plugin is earlier than 0:10.3.181.26-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110871" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0871: tigervnc security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0871-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0871.html" />
          <reference source="CVE" ref_id="CVE-2011-1775" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1775.html" />
    
    <description>Virtual Network Computing (VNC) is a remote display system which allows you
to view a computer's desktop environment not only on the machine where it
is running, but from anywhere on the Internet and from a wide variety of
machine architectures. TigerVNC is a suite of VNC servers and clients.

It was discovered that vncviewer could prompt for and send authentication
credentials to a remote server without first properly validating the
server's X.509 certificate. As vncviewer did not indicate that the
certificate was bad or missing, a man-in-the-middle attacker could use this
flaw to trick a vncviewer client into connecting to a spoofed VNC server,
allowing the attacker to obtain the client's credentials. (CVE-2011-1775)

All tigervnc users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-15" />
        <updated date="2011-06-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1775.html">CVE-2011-1775</cve>
                <bugzilla href="http://bugzilla.redhat.com/702470" id="702470">CVE-2011-1775 tigervnc: vncviewer can send password to server without proper validation of the X.509 certificate</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110871005" comment="tigervnc is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110871006" comment="tigervnc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110871009" comment="tigervnc-server-module is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110871010" comment="tigervnc-server-module is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110871007" comment="tigervnc-server-applet is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110871008" comment="tigervnc-server-applet is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110871011" comment="tigervnc-server is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110871012" comment="tigervnc-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110885" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0885: firefox security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0885-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0885.html" />
          <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html" />
          <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html" />
          <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html" />
          <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html" />
          <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html" />
          <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html" />
          <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html" />
          <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html" />
          <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html" />
          <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html" />
          <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html" />
          <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html" />
          <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox handled malformed JPEG images. A
website containing a malicious JPEG image could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Firefox. A web page
containing malicious content could cause Firefox to crash or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2011-0083, CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375,
CVE-2011-2376)

An integer overflow flaw was found in the way Firefox handled JavaScript
Array objects. A website containing malicious JavaScript could cause
Firefox to execute that JavaScript with the privileges of the user running
Firefox. (CVE-2011-2371)

A use-after-free flaw was found in the way Firefox handled malformed
JavaScript. A website containing malicious JavaScript could cause Firefox
to execute that JavaScript with the privileges of the user running Firefox.
(CVE-2011-2373)

It was found that Firefox could treat two separate cookies as
interchangeable if both were for the same domain name but one of those
domain names had a trailing "." character. This violates the same-origin
policy and could possibly lead to data being leaked to the wrong domain.
(CVE-2011-2362)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.18. You can find a link to the Mozilla
advisories in the References section of this erratum.

This update also fixes the following bug:

* With previous versions of Firefox on Red Hat Enterprise Linux 5, the
"background-repeat" CSS (Cascading Style Sheets) property did not work
(such images were not displayed and repeated as expected). (BZ#698313)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.18, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-21" />
        <updated date="2011-06-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0083.html">CVE-2011-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0085.html">CVE-2011-0085</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2362.html">CVE-2011-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2363.html">CVE-2011-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2364.html">CVE-2011-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2365.html">CVE-2011-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2371.html">CVE-2011-2371</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2373.html">CVE-2011-2373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2374.html">CVE-2011-2374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2375.html">CVE-2011-2375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2376.html">CVE-2011-2376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2377.html">CVE-2011-2377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2605.html">CVE-2011-2605</cve>
                <bugzilla href="http://bugzilla.redhat.com/698313" id="698313">"background-repeat" css property isn't rendered well in Firefox 3.6.x</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714576" id="714576">CVE-2011-2364 CVE-2011-2365 CVE-2011-2374 CVE-2011-2375 CVE-2011-2376 CVE-2011-2605 Mozilla Miscellaneous memory safety hazards (MFSA 2011-19)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714577" id="714577">CVE-2011-2373 Mozilla Use-after-free vulnerability when viewing XUL document with script disabled (MFSA 2011-20)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714580" id="714580">CVE-2011-2371 Mozilla Integer overflow and arbitrary code execution (MFSA 2011-22)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714581" id="714581">CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714583" id="714583">CVE-2011-2362 Mozilla Cookie isolation error (MFSA 2011-24)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714929" id="714929">CVE-2011-2377 Mozilla Crash caused by corrupted JPEG image (MFSA 2011-21)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885002" comment="firefox is earlier than 0:3.6.18-1.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885004" comment="xulrunner is earlier than 0:1.9.2.18-2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885006" comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110885009" comment="firefox is earlier than 0:3.6.18-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885015" comment="firefox is earlier than 0:3.6.18-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885017" comment="xulrunner is earlier than 0:1.9.2.18-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110885019" comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110886" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0886: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0886-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0886.html" />
          <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html" />
          <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html" />
          <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html" />
          <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html" />
          <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html" />
          <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html" />
          <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html" />
          <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html" />
          <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html" />
          <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html" />
          <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Thunderbird. Malicious HTML
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0083,
CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375, CVE-2011-2376)

It was found that Thunderbird could treat two separate cookies (for web
content) as interchangeable if both were for the same domain name but one
of those domain names had a trailing "." character. This violates the
same-origin policy and could possibly lead to data being leaked to the
wrong domain. (CVE-2011-2362)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-21" />
        <updated date="2011-06-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0083.html">CVE-2011-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0085.html">CVE-2011-0085</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2362.html">CVE-2011-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2363.html">CVE-2011-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2364.html">CVE-2011-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2365.html">CVE-2011-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2374.html">CVE-2011-2374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2375.html">CVE-2011-2375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2376.html">CVE-2011-2376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2377.html">CVE-2011-2377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2605.html">CVE-2011-2605</cve>
                <bugzilla href="http://bugzilla.redhat.com/714576" id="714576">CVE-2011-2364 CVE-2011-2365 CVE-2011-2374 CVE-2011-2375 CVE-2011-2376 CVE-2011-2605 Mozilla Miscellaneous memory safety hazards (MFSA 2011-19)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714581" id="714581">CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714583" id="714583">CVE-2011-2362 Mozilla Cookie isolation error (MFSA 2011-24)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714929" id="714929">CVE-2011-2377 Mozilla Crash caused by corrupted JPEG image (MFSA 2011-21)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110886005" comment="thunderbird is earlier than 0:3.1.11-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110887" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0887: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0887-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0887.html" />
          <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html" />
          <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html" />
          <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html" />
          <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html" />
          <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html" />
          <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html" />
          <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html" />
          <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html" />
          <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html" />
          <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html" />
          <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html" />
          <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html" />
          <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled malformed JPEG images. An
HTML mail message containing a malicious JPEG image could cause Thunderbird
to crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2377)

Multiple dangling pointer flaws were found in Thunderbird. Malicious HTML
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2011-0083,
CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375, CVE-2011-2376)

An integer overflow flaw was found in the way Thunderbird handled
JavaScript Array objects. Malicious content could cause Thunderbird to
execute JavaScript with the privileges of the user running Thunderbird.
(CVE-2011-2371)

A use-after-free flaw was found in the way Thunderbird handled malformed
JavaScript. Malicious content could cause Thunderbird to execute JavaScript
with the privileges of the user running Thunderbird. (CVE-2011-2373)

It was found that Thunderbird could treat two separate cookies (for web
content) as interchangeable if both were for the same domain name but one
of those domain names had a trailing "." character. This violates the
same-origin policy and could possibly lead to data being leaked to the
wrong domain. (CVE-2011-2362)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-21" />
        <updated date="2011-06-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0083.html">CVE-2011-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0085.html">CVE-2011-0085</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2362.html">CVE-2011-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2363.html">CVE-2011-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2364.html">CVE-2011-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2365.html">CVE-2011-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2371.html">CVE-2011-2371</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2373.html">CVE-2011-2373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2374.html">CVE-2011-2374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2375.html">CVE-2011-2375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2376.html">CVE-2011-2376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2377.html">CVE-2011-2377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2605.html">CVE-2011-2605</cve>
                <bugzilla href="http://bugzilla.redhat.com/714576" id="714576">CVE-2011-2364 CVE-2011-2365 CVE-2011-2374 CVE-2011-2375 CVE-2011-2376 CVE-2011-2605 Mozilla Miscellaneous memory safety hazards (MFSA 2011-19)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714577" id="714577">CVE-2011-2373 Mozilla Use-after-free vulnerability when viewing XUL document with script disabled (MFSA 2011-20)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714580" id="714580">CVE-2011-2371 Mozilla Integer overflow and arbitrary code execution (MFSA 2011-22)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714581" id="714581">CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714583" id="714583">CVE-2011-2362 Mozilla Cookie isolation error (MFSA 2011-24)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714929" id="714929">CVE-2011-2377 Mozilla Crash caused by corrupted JPEG image (MFSA 2011-21)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110887002" comment="thunderbird is earlier than 0:2.0.0.24-18.el5_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110887005" comment="thunderbird is earlier than 0:1.5.0.12-39.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110888" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0888: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0888-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0888.html" />
          <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html" />
          <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html" />
          <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html" />
          <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html" />
          <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html" />
          <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html" />
          <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html" />
          <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html" />
          <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html" />
          <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html" />
          <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html" />
          <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html" />
          <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled malformed JPEG images. A
website containing a malicious JPEG image could cause SeaMonkey to crash
or, potentially, execute arbitrary code with the privileges of the user
running SeaMonkey. (CVE-2011-2377)

Multiple dangling pointer flaws were found in SeaMonkey. A web page
containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-0083, CVE-2011-0085, CVE-2011-2363)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375,
CVE-2011-2376)

An integer overflow flaw was found in the way SeaMonkey handled JavaScript
Array objects. A website containing malicious JavaScript could cause
SeaMonkey to execute that JavaScript with the privileges of the user
running SeaMonkey. (CVE-2011-2371)

A use-after-free flaw was found in the way SeaMonkey handled malformed
JavaScript. A website containing malicious JavaScript could cause SeaMonkey
to execute that JavaScript with the privileges of the user running
SeaMonkey. (CVE-2011-2373)

It was found that SeaMonkey could treat two separate cookies as
interchangeable if both were for the same domain name but one of those
domain names had a trailing "." character. This violates the same-origin
policy and could possibly lead to data being leaked to the wrong domain.
(CVE-2011-2362)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-21" />
        <updated date="2011-06-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0083.html">CVE-2011-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0085.html">CVE-2011-0085</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2362.html">CVE-2011-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2363.html">CVE-2011-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2364.html">CVE-2011-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2365.html">CVE-2011-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2371.html">CVE-2011-2371</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2373.html">CVE-2011-2373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2374.html">CVE-2011-2374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2375.html">CVE-2011-2375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2376.html">CVE-2011-2376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2377.html">CVE-2011-2377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2605.html">CVE-2011-2605</cve>
                <bugzilla href="http://bugzilla.redhat.com/714576" id="714576">CVE-2011-2364 CVE-2011-2365 CVE-2011-2374 CVE-2011-2375 CVE-2011-2376 CVE-2011-2605 Mozilla Miscellaneous memory safety hazards (MFSA 2011-19)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714577" id="714577">CVE-2011-2373 Mozilla Use-after-free vulnerability when viewing XUL document with script disabled (MFSA 2011-20)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714580" id="714580">CVE-2011-2371 Mozilla Integer overflow and arbitrary code execution (MFSA 2011-22)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714581" id="714581">CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714583" id="714583">CVE-2011-2362 Mozilla Cookie isolation error (MFSA 2011-24)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714929" id="714929">CVE-2011-2377 Mozilla Crash caused by corrupted JPEG image (MFSA 2011-21)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888006" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888010" comment="seamonkey-mail is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888002" comment="seamonkey is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888012" comment="seamonkey-devel is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888008" comment="seamonkey-chat is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110888004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-71.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110908" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0908: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0908-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0908.html" />
          <reference source="CVE" ref_id="CVE-2009-4492" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4492.html" />
          <reference source="CVE" ref_id="CVE-2010-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0541.html" />
          <reference source="CVE" ref_id="CVE-2011-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0188.html" />
          <reference source="CVE" ref_id="CVE-2011-1005" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1005.html" />
    
    <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

It was found that WEBrick (the Ruby HTTP server toolkit) did not filter
terminal escape sequences from its log files. A remote attacker could use
specially-crafted HTTP requests to inject terminal escape sequences into
the WEBrick log files. If a victim viewed the log files with a terminal
emulator, it could result in control characters being executed with the
privileges of that user. (CVE-2009-4492)

A cross-site scripting (XSS) flaw was found in the way WEBrick displayed
error pages. A remote attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted URL. (CVE-2010-0541)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 and CVE-2010-0541 issues.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-28" />
        <updated date="2011-06-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4492.html">CVE-2009-4492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0541.html">CVE-2010-0541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0188.html">CVE-2011-0188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1005.html">CVE-2011-1005</cve>
                <bugzilla href="http://bugzilla.redhat.com/554485" id="554485">CVE-2009-4492 ruby WEBrick log escape sequence</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/587731" id="587731">CVE-2010-0541 Ruby WEBrick javascript injection flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678920" id="678920">CVE-2011-1005 Ruby: Untrusted codes able to modify arbitrary strings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682332" id="682332">CVE-2011-0188 ruby: memory corruption in BigDecimal on 64bit platforms</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908014" comment="ruby-docs is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908015" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908010" comment="irb is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908008" comment="ruby-mode is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908009" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908006" comment="ruby-libs is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908007" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908004" comment="ruby-tcltk is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908005" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908002" comment="ruby is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110908012" comment="ruby-devel is earlier than 0:1.8.1-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110908013" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110909" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0909: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0909-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0909.html" />
          <reference source="CVE" ref_id="CVE-2009-4492" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4492.html" />
          <reference source="CVE" ref_id="CVE-2010-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0541.html" />
          <reference source="CVE" ref_id="CVE-2011-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0188.html" />
          <reference source="CVE" ref_id="CVE-2011-1004" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1004.html" />
          <reference source="CVE" ref_id="CVE-2011-1005" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1005.html" />
    
    <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

A race condition flaw was found in the remove system entries method in the
FileUtils module. If a local user ran a Ruby script that uses this method,
a local attacker could use this flaw to delete arbitrary files and
directories accessible to that user via a symbolic link attack.
(CVE-2011-1004)

It was found that WEBrick (the Ruby HTTP server toolkit) did not filter
terminal escape sequences from its log files. A remote attacker could use
specially-crafted HTTP requests to inject terminal escape sequences into
the WEBrick log files. If a victim viewed the log files with a terminal
emulator, it could result in control characters being executed with the
privileges of that user. (CVE-2009-4492)

A cross-site scripting (XSS) flaw was found in the way WEBrick displayed
error pages. A remote attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted URL. (CVE-2010-0541)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 and CVE-2010-0541 issues.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-28" />
        <updated date="2011-06-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4492.html">CVE-2009-4492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0541.html">CVE-2010-0541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0188.html">CVE-2011-0188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1004.html">CVE-2011-1004</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1005.html">CVE-2011-1005</cve>
                <bugzilla href="http://bugzilla.redhat.com/554485" id="554485">CVE-2009-4492 ruby WEBrick log escape sequence</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/587731" id="587731">CVE-2010-0541 Ruby WEBrick javascript injection flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678913" id="678913">CVE-2011-1004 Ruby: Symlink race condition by removing directory trees in fileutils module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678920" id="678920">CVE-2011-1005 Ruby: Untrusted codes able to modify arbitrary strings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682332" id="682332">CVE-2011-0188 ruby: memory corruption in BigDecimal on 64bit platforms</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909008" comment="ruby-docs is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909009" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909004" comment="ruby-ri is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909005" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909016" comment="ruby-mode is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909017" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909010" comment="ruby-tcltk is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909011" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909006" comment="ruby-libs is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909007" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909018" comment="ruby-irb is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909019" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909014" comment="ruby-rdoc is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909015" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909002" comment="ruby is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110909012" comment="ruby-devel is earlier than 0:1.8.5-19.el5_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110909013" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110910" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0910: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0910-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0910.html" />
          <reference source="CVE" ref_id="CVE-2011-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0188.html" />
          <reference source="CVE" ref_id="CVE-2011-1004" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1004.html" />
          <reference source="CVE" ref_id="CVE-2011-1005" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1005.html" />
    
    <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way large amounts of memory were allocated on
64-bit systems when using the BigDecimal class. A context-dependent
attacker could use this flaw to cause memory corruption, causing a Ruby
application that uses the BigDecimal class to crash or, possibly, execute
arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188)

A race condition flaw was found in the remove system entries method in the
FileUtils module. If a local user ran a Ruby script that uses this method,
a local attacker could use this flaw to delete arbitrary files and
directories accessible to that user via a symbolic link attack.
(CVE-2011-1004)

A flaw was found in the method for translating an exception message into a
string in the Exception class. A remote attacker could use this flaw to
bypass safe level 4 restrictions, allowing untrusted (tainted) code to
modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2011-1005)

Red Hat would like to thank Drew Yao of Apple Product Security for
reporting the CVE-2011-0188 issue.

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-06-28" />
        <updated date="2011-06-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0188.html">CVE-2011-0188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1004.html">CVE-2011-1004</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1005.html">CVE-2011-1005</cve>
                <bugzilla href="http://bugzilla.redhat.com/678913" id="678913">CVE-2011-1004 Ruby: Symlink race condition by removing directory trees in fileutils module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678920" id="678920">CVE-2011-1005 Ruby: Untrusted codes able to modify arbitrary strings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682332" id="682332">CVE-2011-0188 ruby: memory corruption in BigDecimal on 64bit platforms</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910013" comment="ruby-ri is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910014" comment="ruby-ri is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910011" comment="ruby-docs is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910012" comment="ruby-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910019" comment="ruby-libs is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910020" comment="ruby-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910009" comment="ruby-static is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910010" comment="ruby-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910007" comment="ruby-tcltk is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910008" comment="ruby-tcltk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910017" comment="ruby-irb is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910018" comment="ruby-irb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910021" comment="ruby-rdoc is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910022" comment="ruby-rdoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910005" comment="ruby is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910006" comment="ruby is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110910015" comment="ruby-devel is earlier than 0:1.8.7.299-7.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110910016" comment="ruby-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110918" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0918: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0918-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0918.html" />
          <reference source="CVE" ref_id="CVE-2011-2192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2192.html" />
    
    <description>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

It was found that cURL always performed credential delegation when
authenticating with GSSAPI. A rogue server could use this flaw to obtain
the client's credentials and impersonate that client to other servers that
are using GSSAPI. (CVE-2011-2192)

Users of curl should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running applications using
libcurl must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-05" />
        <updated date="2011-07-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2192.html">CVE-2011-2192</cve>
                <bugzilla href="http://bugzilla.redhat.com/711454" id="711454">CVE-2011-2192 curl: Improper delegation of client credentials during GSS negotiation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918002" comment="curl is earlier than 0:7.15.5-9.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918003" comment="curl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918004" comment="curl-devel is earlier than 0:7.15.5-9.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918005" comment="curl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918007" comment="curl is earlier than 0:7.12.1-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918008" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918009" comment="curl-devel is earlier than 0:7.12.1-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918010" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918015" comment="curl is earlier than 0:7.19.7-26.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918016" comment="curl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918017" comment="libcurl-devel is earlier than 0:7.19.7-26.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918018" comment="libcurl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110918019" comment="libcurl is earlier than 0:7.19.7-26.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110918020" comment="libcurl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110919" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0919: qemu-kvm security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0919-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0919.html" />
          <reference source="CVE" ref_id="CVE-2011-2212" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2212.html" />
          <reference source="CVE" ref_id="CVE-2011-2512" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2512.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that the virtio subsystem in qemu-kvm did not properly
validate virtqueue in and out requests from the guest. A privileged guest
user could use this flaw to trigger a buffer overflow, allowing them to
crash the guest (denial of service) or, possibly, escalate their privileges
on the host. (CVE-2011-2212)

It was found that the virtio_queue_notify() function in qemu-kvm did not
perform sufficient input validation on the value later used as an index
into the array of virtqueues. An unprivileged guest user could use this
flaw to crash the guest (denial of service) or, possibly, escalate their
privileges on the host. (CVE-2011-2512)

Red Hat would like to thank Nelson Elhage for reporting CVE-2011-2212.

This update also fixes the following bug:

* A bug was found in the way vhost (in qemu-kvm) set up mappings with the
host kernel's vhost module. This could result in the host kernel's vhost
module not having a complete view of a guest system's memory, if that guest
had more than 4 GB of memory. Consequently, hot plugging a vhost-net
network device and restarting the guest may have resulted in that device no
longer working. (BZ#701771)

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-05" />
        <updated date="2011-07-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2212.html">CVE-2011-2212</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2512.html">CVE-2011-2512</cve>
                <bugzilla href="http://bugzilla.redhat.com/713589" id="713589">CVE-2011-2212 qemu-kvm: virtqueue: too-large indirect descriptor buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/717399" id="717399">CVE-2011-2512 qemu-kvm: OOB memory access caused by negative vq notifies</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110919007" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345010" comment="qemu-kvm-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110919005" comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345006" comment="qemu-kvm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110919009" comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110345008" comment="qemu-img is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110920" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0920: krb5-appl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0920-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0920.html" />
          <reference source="CVE" ref_id="CVE-2011-1526" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1526.html" />
    
    <description>The krb5-appl packages provide Kerberos-aware telnet, ftp, rcp, rsh, and
rlogin clients and servers. While these have been replaced by tools such as
OpenSSH in most environments, they remain in use in others.

It was found that gssftp, a Kerberos-aware FTP server, did not properly
drop privileges. A remote FTP user could use this flaw to gain unauthorized
read or write access to files that are owned by the root group.
(CVE-2011-1526)

Red Hat would like to thank the MIT Kerberos project for reporting this
issue. Upstream acknowledges Tim Zingelman as the original reporter.

All krb5-appl users should upgrade to these updated packages, which contain
a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-05" />
        <updated date="2011-07-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1526.html">CVE-2011-1526</cve>
                <bugzilla href="http://bugzilla.redhat.com/711419" id="711419">CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110920007" comment="krb5-appl-servers is earlier than 0:1.0.1-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110920008" comment="krb5-appl-servers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110920009" comment="krb5-appl-clients is earlier than 0:1.0.1-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110920010" comment="krb5-appl-clients is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110920005" comment="krb5-appl is earlier than 0:1.0.1-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110920006" comment="krb5-appl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110926" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0926: bind security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0926-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0926.html" />
          <reference source="CVE" ref_id="CVE-2011-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2464.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS requests. A
remote attacker could use this flaw to send a specially-crafted DNS request
packet to BIND, causing it to exit unexpectedly due to a failed assertion.
(CVE-2011-2464)

Users of bind97 on Red Hat Enterprise Linux 5, and bind on Red Hat
Enterprise Linux 6, are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-07" />
        <updated date="2011-07-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2464.html">CVE-2011-2464</cve>
                <bugzilla href="http://bugzilla.redhat.com/718966" id="718966">CVE-2011-2464 bind: Specially constructed packet will cause named to exit</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926008" comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845009" comment="bind97-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926004" comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845005" comment="bind97-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926010" comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845011" comment="bind97-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926002" comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845003" comment="bind97 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926006" comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845007" comment="bind97-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926026" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845019" comment="bind-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926020" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845021" comment="bind-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926018" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845027" comment="bind-chroot is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926022" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845023" comment="bind-sdb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926016" comment="bind is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845017" comment="bind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110926024" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845025" comment="bind-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110927" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0927: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0927-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0927.html" />
          <reference source="CVE" ref_id="CVE-2010-4649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4649.html" />
          <reference source="CVE" ref_id="CVE-2011-0695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0695.html" />
          <reference source="CVE" ref_id="CVE-2011-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0711.html" />
          <reference source="CVE" ref_id="CVE-2011-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1044.html" />
          <reference source="CVE" ref_id="CVE-2011-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1182.html" />
          <reference source="CVE" ref_id="CVE-2011-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1573.html" />
          <reference source="CVE" ref_id="CVE-2011-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1576.html" />
          <reference source="CVE" ref_id="CVE-2011-1593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1593.html" />
          <reference source="CVE" ref_id="CVE-2011-1745" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1745.html" />
          <reference source="CVE" ref_id="CVE-2011-1746" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1746.html" />
          <reference source="CVE" ref_id="CVE-2011-1776" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1776.html" />
          <reference source="CVE" ref_id="CVE-2011-1936" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1936.html" />
          <reference source="CVE" ref_id="CVE-2011-2022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2022.html" />
          <reference source="CVE" ref_id="CVE-2011-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2213.html" />
          <reference source="CVE" ref_id="CVE-2011-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2492.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* An integer overflow flaw in ib_uverbs_poll_cq() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2010-4649, Important)

* A race condition in the way new InfiniBand connections were set up could
allow a remote user to cause a denial of service. (CVE-2011-0695,
Important)

* A flaw in the Stream Control Transmission Protocol (SCTP) implementation
could allow a remote attacker to cause a denial of service if the sysctl
"net.sctp.addip_enable" variable was turned on (it is off by default).
(CVE-2011-1573, Important)

* Flaws in the AGPGART driver implementation when handling certain IOCTL
commands could allow a local, unprivileged user to cause a denial of
service or escalate their privileges. (CVE-2011-1745, CVE-2011-2022,
Important)

* An integer overflow flaw in agp_allocate_memory() could allow a local,
unprivileged user to cause a denial of service or escalate their
privileges. (CVE-2011-1746, Important)

* A flaw allowed napi_reuse_skb() to be called on VLAN (virtual LAN)
packets. An attacker on the local network could trigger this flaw by
sending specially-crafted packets to a target system, possibly causing a
denial of service. (CVE-2011-1576, Moderate)

* An integer signedness error in next_pidmap() could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-1593, Moderate)

* A flaw in the way the Xen hypervisor implementation handled CPUID
instruction emulation during virtual machine exits could allow an
unprivileged guest user to crash a guest. This only affects systems that
have an Intel x86 processor with the Intel VT-x extension enabled.
(CVE-2011-1936, Moderate)

* A flaw in inet_diag_bc_audit() could allow a local, unprivileged user to
cause a denial of service (infinite loop). (CVE-2011-2213, Moderate)

* A missing initialization flaw in the XFS file system implementation
could lead to an information leak. (CVE-2011-0711, Low)

* A flaw in ib_uverbs_poll_cq() could allow a local, unprivileged user to
cause an information leak. (CVE-2011-1044, Low)

* A missing validation check was found in the signals implementation. A
local, unprivileged user could use this flaw to send signals via the
sigqueueinfo system call, with the si_code set to SI_TKILL and with spoofed
process and user IDs, to other processes. Note: This flaw does not allow
existing permission checks to be bypassed; signals can only be sent if your
privileges allow you to already do so. (CVE-2011-1182, Low)

* A heap overflow flaw in the EFI GUID Partition Table (GPT) implementation
could allow a local attacker to cause a denial of service by mounting a
disk containing specially-crafted partition tables. (CVE-2011-1776, Low)

* Structure padding in two structures in the Bluetooth implementation
was not initialized properly before being copied to user-space, possibly
allowing local, unprivileged users to leak kernel stack memory to
user-space. (CVE-2011-2492, Low)

Red Hat would like to thank Jens Kuehnel for reporting CVE-2011-0695;
Vasiliy Kulikov for reporting CVE-2011-1745, CVE-2011-2022, and
CVE-2011-1746; Ryan Sweat for reporting CVE-2011-1576; Robert Swiecki for
reporting CVE-2011-1593; Dan Rosenberg for reporting CVE-2011-2213 and
CVE-2011-0711; Julien Tinnes of the Google Security Team for reporting
CVE-2011-1182; Timo Warns for reporting CVE-2011-1776; and Marek Kroemeke
and Filip Palian for reporting CVE-2011-2492.

Bug fix documentation will be available shortly from the Technical Notes
document linked to in the References.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-15" />
        <updated date="2011-07-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4649.html">CVE-2010-4649</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0695.html">CVE-2011-0695</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0711.html">CVE-2011-0711</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1044.html">CVE-2011-1044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1182.html">CVE-2011-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1573.html">CVE-2011-1573</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1576.html">CVE-2011-1576</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1593.html">CVE-2011-1593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1745.html">CVE-2011-1745</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1746.html">CVE-2011-1746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1776.html">CVE-2011-1776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1936.html">CVE-2011-1936</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2022.html">CVE-2011-2022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2213.html">CVE-2011-2213</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2492.html">CVE-2011-2492</cve>
                <bugzilla href="http://bugzilla.redhat.com/653648" id="653648">CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667916" id="667916">CVE-2010-4649 CVE-2011-1044 kernel: IB/uverbs: Handle large number of entries in poll CQ</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677260" id="677260">CVE-2011-0711 kernel: xfs: prevent leaking uninitialized stack memory in FSGEOMETRY_V1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690028" id="690028">CVE-2011-1182 kernel signal spoofing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695173" id="695173">CVE-2011-1576 kernel: net: Fix memory leak/corruption on VLAN GRO_DROP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695383" id="695383">CVE-2011-1573 kernel: sctp: fix to calc the INIT/INIT-ACK chunk length correctly to set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697822" id="697822">CVE-2011-1593 kernel: proc: signedness issue in next_pidmap()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698996" id="698996">CVE-2011-1745 CVE-2011-2022 kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698998" id="698998">CVE-2011-1746 kernel: agp: insufficient page_count parameter checking in agp_allocate_memory()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703019" id="703019">CVE-2011-2492 kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703026" id="703026">CVE-2011-1776 kernel: validate size of EFI GUID partition entries</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703056" id="703056">[RHEL5.5] Panic in iscsi_sw_tcp_data_ready() [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706323" id="706323">CVE-2011-1936 kernel: xen: vmx: insecure cpuid vmexit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/707899" id="707899">The pci resource for vf is not released after hot-removing Intel 82576 NIC [rhel-5.6.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711519" id="711519">GFS2: resource group bitmap corruption resulting in panics and withdraws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714536" id="714536">CVE-2011-2213 kernel: inet_diag: insufficient validation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927004" comment="kernel-headers is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927002" comment="kernel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927024" comment="kernel-doc is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927022" comment="kernel-PAE-devel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927008" comment="kernel-devel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927006" comment="kernel-debug is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927018" comment="kernel-kdump is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927014" comment="kernel-xen-devel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927012" comment="kernel-debug-devel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927020" comment="kernel-PAE is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927016" comment="kernel-kdump-devel is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110927010" comment="kernel-xen is earlier than 0:2.6.18-238.19.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110928" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0928: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0928-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0928.html" />
          <reference source="CVE" ref_id="CVE-2011-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1767.html" />
          <reference source="CVE" ref_id="CVE-2011-1768" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1768.html" />
          <reference source="CVE" ref_id="CVE-2011-2479" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2479.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the receive hook in the ipip_init() function in the
ipip module, and in the ipgre_init() function in the ip_gre module, could
be called before network namespaces setup is complete. If packets were
received at the time the ipip or ip_gre module was still being loaded into
the kernel, it could cause a denial of service. (CVE-2011-1767,
CVE-2011-1768, Moderate)

* It was found that an mmap() call with the MAP_PRIVATE flag on "/dev/zero"
would create transparent hugepages and trigger a certain robustness check.
A local, unprivileged user could use this flaw to cause a denial of
service. (CVE-2011-2479, Moderate)

This update also fixes various bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-12" />
        <updated date="2011-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1767.html">CVE-2011-1767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1768.html">CVE-2011-1768</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2479.html">CVE-2011-2479</cve>
                <bugzilla href="http://bugzilla.redhat.com/702303" id="702303">CVE-2011-1767 CVE-2011-1768 kernel: netns vs proto registration ordering</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711546" id="711546">RHEL6.1 x86_64 HVM guest crashes on AMD host when guest memory size is larger than 8G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/712413" id="712413">Cannot find the extended attribute of #11 inode after remount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/712414" id="712414">[RHEL6.1] [Kernel] Panic while running testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/713135" id="713135">MLS - cgconfigparser cannot search on /cgroup/ dirs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/713458" id="713458">intel-iommu: missing flush prior to removing domains + avoid broken vm/si domain unlinking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714190" id="714190">System Hang when there is smart error on IBM platform</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714761" id="714761">CVE-2011-2479 kernel: thp: madvise on top of /dev/zero private mapping can lead to panic</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928023" comment="kernel-firmware is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928009" comment="kernel-headers is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928005" comment="kernel is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928025" comment="kernel-doc is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928013" comment="kernel-devel is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928017" comment="perf is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928011" comment="kernel-debug is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928019" comment="kernel-kdump is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928015" comment="kernel-debug-devel is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928021" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110928007" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.6.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110930" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0930: NetworkManager security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0930-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0930.html" />
          <reference source="CVE" ref_id="CVE-2011-2176" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2176.html" />
    
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

It was found that NetworkManager did not properly enforce PolicyKit
settings controlling the permissions to configure wireless network sharing.
A local, unprivileged user could use this flaw to bypass intended PolicyKit
restrictions, allowing them to enable wireless network sharing.
(CVE-2011-2176)

Users of NetworkManager should upgrade to these updated packages, which
contain a backported patch to correct this issue. Running instances of
NetworkManager must be restarted ("service NetworkManager restart") for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-12" />
        <updated date="2011-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2176.html">CVE-2011-2176</cve>
                <bugzilla href="http://bugzilla.redhat.com/709662" id="709662">CVE-2011-2176 NetworkManager: Did not honour PolicyKit auth_admin action element by creation of Ad-Hoc wireless networks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110930009" comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930010" comment="NetworkManager-glib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110930013" comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930014" comment="NetworkManager-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110930007" comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930008" comment="NetworkManager-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110930011" comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930012" comment="NetworkManager-glib-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110930005" comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930006" comment="NetworkManager is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110938" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0938: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0938-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0938.html" />
          <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html" />
          <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html" />
          <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
          <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2011-0802, CVE-2011-0814,
CVE-2011-0862, CVE-2011-0863, CVE-2011-0865, CVE-2011-0867, CVE-2011-0868,
CVE-2011-0869, CVE-2011-0871, CVE-2011-0873)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR9-FP2 Java release. All running
instances of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-15" />
        <updated date="2011-07-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0802.html">CVE-2011-0802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0814.html">CVE-2011-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0863.html">CVE-2011-0863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0868.html">CVE-2011-0868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0869.html">CVE-2011-0869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0873.html">CVE-2011-0873</cve>
                <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706234" id="706234">CVE-2011-0869 OpenJDK: unprivileged proxy settings change via SOAPConnection (SAAJ, 7013971)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706241" id="706241">CVE-2011-0868 OpenJDK: incorrect numeric type conversion in TransformHelper (2D, 7016495)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711675" id="711675">CVE-2011-0873 Oracle/IBM JDK: unspecified vulnerability fixed in 6u26 (2D)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711676" id="711676">CVE-2011-0863 Oracle/IBM JDK: unspecified vulnerability fixed in 6u26 (Deployment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711677" id="711677">CVE-2011-0802 CVE-2011-0814 Oracle/IBM JDK: unspecified vulnerabilities fixed in 6u26 (Sound)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938004" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290013" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938014" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938010" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290005" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938016" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290015" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938008" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290011" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938012" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290017" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938006" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290007" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938030" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290029" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938022" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290023" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938034" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290033" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938032" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290027" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938026" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290035" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938028" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290031" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110938024" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110290025" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110953" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0953: system-config-firewall security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0953-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0953.html" />
          <reference source="CVE" ref_id="CVE-2011-2520" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2520.html" />
    
    <description>system-config-firewall is a graphical user interface for basic firewall
setup.

It was found that system-config-firewall used the Python pickle module in
an insecure way when sending data (via D-Bus) to the privileged back-end
mechanism. A local user authorized to configure firewall rules using
system-config-firewall could use this flaw to execute arbitrary code with
root privileges, by sending a specially-crafted serialized object.
(CVE-2011-2520)

Red Hat would like to thank Marco Slaviero of SensePost for reporting this
issue.

This erratum updates system-config-firewall to use JSON (JavaScript Object
Notation) for data exchange, instead of pickle. Therefore, an updated
version of system-config-printer that uses this new communication data
format is also provided in this erratum.

Users of system-config-firewall are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. Running
instances of system-config-firewall must be restarted before the utility
will be able to communicate with its updated back-end.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-18" />
        <updated date="2011-07-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2520.html">CVE-2011-2520</cve>
                <bugzilla href="http://bugzilla.redhat.com/717985" id="717985">CVE-2011-2520 system-config-firewall: privilege escalation flaw via use of python pickle</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953009" comment="system-config-firewall-tui is earlier than 0:1.2.27-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953010" comment="system-config-firewall-tui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953005" comment="system-config-firewall is earlier than 0:1.2.27-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953006" comment="system-config-firewall is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953007" comment="system-config-firewall-base is earlier than 0:1.2.27-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953008" comment="system-config-firewall-base is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953013" comment="system-config-printer-udev is earlier than 0:1.1.16-17.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953014" comment="system-config-printer-udev is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953015" comment="system-config-printer-libs is earlier than 0:1.1.16-17.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953016" comment="system-config-printer-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110953011" comment="system-config-printer is earlier than 0:1.1.16-17.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110953012" comment="system-config-printer is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110959" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0959: mutt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0959-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0959.html" />
          <reference source="CVE" ref_id="CVE-2011-1429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1429.html" />
    
    <description>Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt verified SSL certificates. When a server
presented an SSL certificate chain, Mutt could ignore a server hostname
check failure. A remote attacker able to get a certificate from a trusted
Certificate Authority could use this flaw to trick Mutt into accepting a
certificate issued for a different hostname, and perform man-in-the-middle
attacks against Mutt's SSL connections. (CVE-2011-1429)

All Mutt users should upgrade to this updated package, which contains a
backported patch to correct this issue. All running instances of Mutt must
be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-19" />
        <updated date="2011-07-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1429.html">CVE-2011-1429</cve>
                <bugzilla href="http://bugzilla.redhat.com/688755" id="688755">CVE-2011-1429 mutt: SSL host name check may be skipped when verifying certificate chain</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110959005" comment="mutt is earlier than 5:1.5.20-2.20091214hg736b6a.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110959006" comment="mutt is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110975" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0975: sssd security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0975-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0975.html" />
          <reference source="CVE" ref_id="CVE-2010-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4341.html" />
    
    <description>The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.

A flaw was found in the SSSD PAM responder that could allow a local
attacker to force SSSD to enter an infinite loop via a carefully-crafted
packet. With SSSD unresponsive, legitimate users could be denied the
ability to log in to the system. (CVE-2010-4341)

Red Hat would like to thank Sebastian Krahmer for reporting this issue.

These updated sssd packages include a number of bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory. Refer to
the Red Hat Enterprise Linux 5.7 Technical Notes for information about
these changes:

https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.7_Technical_Notes/sssd.html#RHSA-2011-0975

All sssd users are advised to upgrade to these updated sssd packages, which
upgrade SSSD to upstream version 1.5.1 to correct this issue, and fix the
bugs and add the enhancements noted in the Technical Notes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4341.html">CVE-2010-4341</cve>
                <bugzilla href="http://bugzilla.redhat.com/640601" id="640601">sssd is not escaping correctly LDAP searches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661163" id="661163">CVE-2010-4341 sssd: DoS in sssd PAM responder can prevent logins</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675007" id="675007">sssd corrupts group cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/676027" id="676027">sssd segfault when first entry of ldap_uri is unreachable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678032" id="678032">Remove HBAC time rules from SSSD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678092" id="678092">SSSD in 5.6 can not locate HBAC rules from FreeIPAv2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678412" id="678412">name service caches names, so id command shows recently deleted users</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678606" id="678606">User information not updated on login for secondary domains</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678615" id="678615">SSSD needs to look at IPA's compat tree for netgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678778" id="678778">IPA provider does not update removed group memberships on initgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678780" id="678780">sssd crashes at the next tgt renewals it tries.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679087" id="679087">SSSD IPA provider should honor the krb5_realm option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679097" id="679097">Does not read renewable ccache at startup.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682803" id="682803">sssd-be segmentation fault - ipa-client on ipa-server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682808" id="682808">sssd_nss core dumps with certain lookups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/682853" id="682853">IPA provider should use realm instead of ipa_domain for base DN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683260" id="683260">sudo/ldap lookup via sssd gets stuck for 5min waiting on netgroup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688677" id="688677">Build SSSD in RHEL 5.7 against openldap24-libs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688694" id="688694">authconfig fails when access_provider is set as krb5 in sssd.conf.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688697" id="688697">sssd 1.5.1-9 breaks AD authentication</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689887" id="689887">group memberships are not populated correctly during IPA provider initgroups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690093" id="690093">multiple problems with sssd + ldap (Active-Directory) and groups members.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690096" id="690096">SSSD should skip over groups with multiple names</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690287" id="690287">Traceback messages seen while interrupting sss_obfuscate using ctrl+d.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690814" id="690814">[abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690867" id="690867">Groups with a zero-length memberuid attribute can cause SSSD to stop caching and responding to requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/691900" id="691900">SSSD needs to fall back to 'cn' for GECOS information (was: SSSD configuration problem when configured with MSAD)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692960" id="692960">Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694149" id="694149">SSSD consumes GBs of RAM, possible memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694853" id="694853">SSSD crashes during getent when anonymous bind is disabled.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695476" id="695476">Unable to resolve SRV record when called with _srv_,&lt;fixed ldap uri> in ldap_uri</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696979" id="696979">[REGRESSION] Filters not honoured against fully-qualified users.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/701702" id="701702">sssd client libraries use select() but should use poll() instead</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/707340" id="707340">latest sssd fails if ldap_default_authtok_type is not mentioned</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/707574" id="707574">SSSD's async resolver only tries the first nameserver in /etc/resolv.conf</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110975002" comment="sssd is earlier than 0:1.5.1-37.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110975003" comment="sssd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110975006" comment="sssd-client is earlier than 0:1.5.1-37.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110975007" comment="sssd-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110975004" comment="sssd-tools is earlier than 0:1.5.1-37.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110975005" comment="sssd-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20110999" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:0999: rsync security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:0999-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0999.html" />
          <reference source="CVE" ref_id="CVE-2007-6200" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6200.html" />
    
    <description>rsync is a program for synchronizing files over a network.

A flaw was found in the way the rsync daemon handled the "filter",
"exclude", and "exclude from" options, used for hiding files and preventing
access to them from rsync clients. A remote attacker could use this flaw to
bypass those restrictions by using certain command line options and
symbolic links, allowing the attacker to overwrite those files if they knew
their file names and had write access to them. (CVE-2007-6200)

Note: This issue only affected users running rsync as a writable daemon:
"read only" set to "false" in the rsync configuration file (for example,
"/etc/rsyncd.conf"). By default, this option is set to "true".

This update also fixes the following bugs:

* The rsync package has been upgraded to upstream version 3.0.6, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#339971)

* When running an rsync daemon that was receiving files, a deferred info,
error or log message could have been sent directly to the sender instead of
being handled by the "rwrite()" function in the generator. Also, under
certain circumstances, a deferred info or error message from the receiver
could have bypassed the log file and could have been sent only to the
client process. As a result, an "unexpected tag 3" fatal error could have
been displayed. These problems have been fixed in this update so that an
rsync daemon receiving files now works as expected. (BZ#471182)

* Prior to this update, the rsync daemon called a number of timezone-using
functions after doing a chroot. As a result, certain C libraries were
unable to generate proper timestamps from inside a chrooted daemon. This
bug has been fixed in this update so that the rsync daemon now calls the
respective timezone-using functions prior to doing a chroot, and proper
timestamps are now generated as expected. (BZ#575022)

* When running rsync under a non-root user with the "-A" ("--acls") option
and without using the "--numeric-ids" option, if there was an Access
Control List (ACL) that included a group entry for a group that the
respective user was not a member of on the receiving side, the
"acl_set_file()" function returned an invalid argument value ("EINVAL").
This was caused by rsync mistakenly mapping the group name to the Group ID
"GID_NONE" ("-1"), which failed. The bug has been fixed in this update so
that no invalid argument is returned and rsync works as expected.
(BZ#616093)

* When creating a sparse file that was zero blocks long, the "rsync
--sparse" command did not properly truncate the sparse file at the end of
the copy transaction. As a result, the file size was bigger than expected.
This bug has been fixed in this update by properly truncating the file so
that rsync now copies such files as expected. (BZ#530866)

* Under certain circumstances, when using rsync in daemon mode, rsync
generator instances could have entered an infinitive loop, trying to write
an error message for the receiver to an invalid socket. This problem has
been fixed in this update by adding a new sibling message: when the
receiver is reporting a socket-read error, the generator will notice this
fact and avoid writing an error message down the socket, allowing it to
close down gracefully when the pipe from the receiver closes. (BZ#690148)

* Prior to this update, there were missing deallocations found in the
"start_client()" function. This bug has been fixed in this update and no
longer occurs. (BZ#700450)

All users of rsync are advised to upgrade to this updated package, which
resolves these issues and adds enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6200.html">CVE-2007-6200</cve>
                <bugzilla href="http://bugzilla.redhat.com/339971" id="339971">[RFE] Rebase rsync packages to version 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/407171" id="407171">CVE-2007-6200 rsync excluded content access restrictions bypass via symlinks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471182" id="471182">rsync errors: unexpected tag 3 [sender]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530866" id="530866">rsync --sparse does not properly copy sparse files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/575022" id="575022">rsyncd gets confused with timezones when logging to syslog</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/616093" id="616093">EINVAL (Invalid argument) setting group --acls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690148" id="690148">Rsync instances stay in memory when using in daemon mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700450" id="700450">Resource leaks revealed by Coverity scan.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110999002" comment="rsync is earlier than 0:3.0.6-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110999003" comment="rsync is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111000" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1000: rgmanager security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1000-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1000.html" />
          <reference source="CVE" ref_id="CVE-2010-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3389.html" />
    
    <description>The rgmanager package contains the Red Hat Resource Group Manager, which
provides the ability to create and manage high-availability server
applications in the event of system downtime.

It was discovered that certain resource agent scripts set the
LD_LIBRARY_PATH environment variable to an insecure value containing empty
path elements. A local user able to trick a user running those scripts to
run them while working from an attacker-writable directory could use this
flaw to escalate their privileges via a specially-crafted dynamic library.
(CVE-2010-3389)

Red Hat would like to thank Raphael Geissert for reporting this issue.

This update also fixes the following bugs:

* The failover domain "nofailback" option was not honored if a service was
in the "starting" state. This bug has been fixed. (BZ#669440)

* PID files with white spaces in the file name are now handled correctly.
(BZ#632704)

* The /usr/sbin/rhev-check.sh script can now be used from within Cron.
(BZ#634225)

* The clustat utility now reports the correct version. (BZ#654160)

* The oracledb.sh agent now attempts to try the "shutdown immediate"
command instead of using the "shutdown abort" command. (BZ#633992)

* The SAPInstance and SAPDatabase scripts now use proper directory name
quoting so they no longer collide with directory names like "/u".
(BZ#637154)

* The clufindhostname utility now returns the correct value in all cases.
(BZ#592613)

* The nfsclient resource agent now handles paths with trailing slashes
correctly. (BZ#592624)

* The last owner of a service is now reported correctly after a failover.
(BZ#610483)

* The /usr/share/cluster/fs.sh script no longer runs the "quotaoff" command
if quotas were not configured. (BZ#637678)

* The "listen" line in the /etc/httpd/conf/httpd.conf file generated by the
Apache resource agent is now correct. (BZ#675739)

* The tomcat-5 resource agent no longer generates incorrect configurations.
(BZ#637802)

* The time required to stop an NFS resource when the server is unavailable
has been reduced. (BZ#678494)

* When using exclusive prioritization, a higher priority service now
preempts a lower priority service after status check failures. (BZ#680256)

* The postgres-8 resource agent now correctly detects failed start
operations. (BZ#663827)

* The handling of reference counts passed by rgmanager to resource agents
now works properly, as expected. (BZ#692771)

As well, this update adds the following enhancements:

* It is now possible to disable updates to static routes by the IP resource
agent. (BZ#620700)

* It is now possible to use XFS as a file system within a cluster service.
(BZ#661893)

* It is now possible to use the "clustat" command as a non-root user, so
long as that user is in the "root" group. (BZ#510300)

* It is now possible to migrate virtual machines when central processing is
enabled. (BZ#525271)

* The rgmanager init script will now delay after stopping services in order
to allow time for other nodes to restart them. (BZ#619468)

* The handling of failed independent subtrees has been corrected.
(BZ#711521)

All users of Red Hat Resource Group Manager are advised to upgrade to this
updated package, which contains backported patches to correct these issues
and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3389.html">CVE-2010-3389</cve>
                <bugzilla href="http://bugzilla.redhat.com/592613" id="592613">clufindhostname -i returns random value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592624" id="592624">nfsclient exports doens't work.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/610483" id="610483">last_owner is not correctly updated on service reallocarion on failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632704" id="632704">If whitespace in mysql resource name then pid file is not found</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/634225" id="634225">rhev-check.sh needs /usr/sbin in path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637154" id="637154">SAPInstance and SAPDatabase fail to start/stop/status if /u exists</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637678" id="637678">service failover hangs at quotaoff in /usr/share/cluster/fs.sh</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637802" id="637802">Fix problems in generated config file for tomcat-5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/639044" id="639044">CVE-2010-3389 rgmanager: insecure library loading vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654160" id="654160">clustat -v reports "clustat version DEVEL" on release package</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661893" id="661893">Support/testing of XFS filesystem as part of RHEL Cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663827" id="663827">postgres-8 resource agent does not detect a failed start of postgres server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669440" id="669440">Service will failback on "nofailback" failover domain if service is in "starting" state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675739" id="675739">Listen line in generated httpd.conf incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678494" id="678494">netfs.sh patch, when network is lost it takes too long to unmount the NFS filesystems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680256" id="680256">Service with highest exclusive prio should be relocated to another node with lower exclusive prio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711521" id="711521">Dependencies in independent_tree resources does not work as expected</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_cluster</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111000002" comment="rgmanager is earlier than 0:2.0.52-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111000003" comment="rgmanager is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111005" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1005.html" />
          <reference source="CVE" ref_id="CVE-2007-3852" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3852.html" />
    
    <description>The sysstat package contains a set of utilities which enable system
monitoring of disks, network, and other I/O activity.

It was found that the sysstat initscript created a temporary file in an
insecure way. A local attacker could use this flaw to create arbitrary
files via a symbolic link attack. (CVE-2007-3852)

This update fixes the following bugs:

* On systems under heavy load, the sadc utility would sometimes output the
following error message if a write() call was unable to write all of the
requested input:

"Cannot write data to system activity file: Success."

In this updated package, the sadc utility tries to write the remaining
input, resolving this issue. (BZ#454617)

* On the Itanium architecture, the "sar -I" command provided incorrect
information about the interrupt statistics of the system. With this update,
the "sar -I" command has been disabled for this architecture, preventing
this bug. (BZ#468340)

* Previously, the "iostat -n" command used invalid data to create
statistics for read and write operations. With this update, the data source
for these statistics has been fixed, and the iostat utility now returns
correct information. (BZ#484439)

* The "sar -d" command used to output invalid data about block devices.
With this update, the sar utility recognizes disk registration and disk
overflow statistics properly, and only correct and relevant data is now
displayed. (BZ#517490)

* Previously, the sar utility set the maximum number of days to be logged
in one month too high. Consequently, data from a month was appended to
data from the preceding month. With this update, the maximum number of days
has been set to 25, and data from a month now correctly replaces data from
the preceding month. (BZ#578929)

* In previous versions of the iostat utility, the number of NFS mount
points was hard-coded. Consequently, various issues occurred while iostat
was running and NFS mount points were mounted or unmounted; certain values
in iostat reports overflowed and some mount points were not reported at
all. With this update, iostat properly recognizes when an NFS mount point
mounts or unmounts, fixing these issues. (BZ#675058, BZ#706095, BZ#694767)

* When a device name was longer than 13 characters, the iostat utility
printed a redundant new line character, making its output less readable.
This bug has been fixed and now, no extra characters are printed if a long
device name occurs in iostat output. (BZ#604637)

* Previously, if kernel interrupt counters overflowed, the sar utility
provided confusing output. This bug has been fixed and the sum of
interrupts is now reported correctly. (BZ#622557)

* When some processors were disabled on a multi-processor system, the sar
utility sometimes failed to provide information about the CPU activity.
With this update, the uptime of a single processor is used to compute the
statistics, rather than the total uptime of all processors, and this bug no
longer occurs. (BZ#630559)

* Previously, the mpstat utility wrongly interpreted data about processors
in the system. Consequently, it reported a processor that did not exist.
This bug has been fixed and non-existent CPUs are no longer reported by
mpstat. (BZ#579409)

* Previously, there was no easy way to enable the collection of statistics
about disks and interrupts. Now, the SADC_OPTIONS variable can be used to
set parameters for the sadc utility, fixing this bug. (BZ#598794)

* The read_uptime() function failed to close its open file upon exit. A
patch has been provided to fix this bug. (BZ#696672)

This update also adds the following enhancement:

* With this update, the cifsiostat utility has been added to the sysstat
package to provide CIFS (Common Internet File System) mount point I/O
statistics. (BZ#591530)

All sysstat users are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add this
enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3852.html">CVE-2007-3852</cve>
                <bugzilla href="http://bugzilla.redhat.com/251200" id="251200">CVE-2007-3852 sysstat insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454617" id="454617">[RHEL5] Though function write() executed sucessful, sadc end with an error.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484439" id="484439">iostat -n enhancement not report NFS client stats correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517490" id="517490">The 'sar -d ' command outputs invalid data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/578929" id="578929">March sar data was appended to February data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/579409" id="579409">The sysstat's programs such as mpstat shows one extra cpu.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/598794" id="598794">Enable parametrization of sadc arguments</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/604637" id="604637">extraneous newline in iostat report for long device names</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622557" id="622557">sar interrupt count goes backward</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/630559" id="630559">'sar -P ALL -f xxxx ' does not display activity information.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675058" id="675058">iostat: bogus value appears when device is unmounted/mounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/694767" id="694767">iostat doesn't report statistics for shares with long names</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696672" id="696672">Resource leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706095" id="706095">iostat -n - values in output overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111005002" comment="sysstat is earlier than 0:7.0.2-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111005003" comment="sysstat is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111019" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1019: libvirt security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1019.html" />
          <reference source="CVE" ref_id="CVE-2011-2511" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2511.html" />
    
    <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.

An integer overflow flaw was found in libvirtd's RPC call handling. An
attacker able to establish read-only connections to libvirtd could trigger
this flaw by calling virDomainGetVcpus() with specially-crafted parameters,
causing libvirtd to crash. (CVE-2011-2511)

This update fixes the following bugs:

* libvirt was rebased from version 0.6.3 to version 0.8.2 in Red Hat
Enterprise Linux 5.6. A code audit found a minor API change that effected
error messages seen by libvirt 0.8.2 clients talking to libvirt 0.7.1 –
0.7.7 (0.7.x) servers. A libvirt 0.7.x server could send
VIR_ERR_BUILD_FIREWALL errors where a libvirt 0.8.2 client expected
VIR_ERR_CONFIG_UNSUPPORTED errors. In other circumstances, a libvirt 0.8.2
client saw a "Timed out during operation" message where it should see an
"Invalid network filter" error. This update adds a backported patch that
allows libvirt 0.8.2 clients to interoperate with the API as used by
libvirt 0.7.x servers, ensuring correct error messages are sent.
(BZ#665075)

* libvirt could crash if the maximum number of open file descriptors
(_SC_OPEN_MAX) grew larger than the FD_SETSIZE value because it accessed
file descriptors outside the bounds of the set. With this update the
maximum number of open file descriptors can no longer grow larger than the
FD_SETSIZE value. (BZ#665549)

* A libvirt race condition was found. An array in the libvirt event
handlers was accessed with a lock temporarily released. In rare cases, if
one thread attempted to access this array but a second thread reallocated
the array before the first thread reacquired a lock, it could lead to the
first thread attempting to access freed memory, potentially causing libvirt
to crash. With this update libvirt no longer refers to the old array and,
consequently, behaves as expected. (BZ#671569)

* Guests connected to a passthrough NIC would kernel panic if a
system_reset signal was sent through the QEMU monitor. With this update you
can reset such guests as expected. (BZ#689880)

* When using the Xen kernel, the rpmbuild command failed on the xencapstest
test. With this update you can run rpmbuild successfully when using the Xen
kernel. (BZ#690459)

* When a disk was hot unplugged, "ret >= 0" was passed to the qemuAuditDisk
calls in disk hotunplug operations before ret was, in fact, set to 0. As
well, the error path jumped to the "cleanup" label prematurely. As a
consequence, hotunplug failures were not audited and hotunplug successes
were audited as failures. This was corrected and hot unplugging checks now
behave as expected. (BZ#710151)

* A conflict existed between filter update locking sequences and virtual
machine startup locking sequences. When a filter update occurred on one or
more virtual machines, a deadlock could consequently occur if a virtual
machine referencing a filter was started. This update changes and makes
more flexible several qemu locking sequences ensuring this deadlock no
longer occurs. (BZ#697749)

* qemudDomainSaveImageStartVM closed some incoming file descriptor (fd)
arguments without informing the caller. The consequent double-closes could
cause Domain restoration failure. This update alters the
qemudDomainSaveImageStartVM signature to prevent the double-closes.
(BZ#681623)

This update also adds the following enhancements:

* The libvirt Xen driver now supports more than one serial port.
(BZ#670789)

* Enabling and disabling the High Precision Event Timer (HPET) in Xen
domains is now possible. (BZ#703193)

All libvirt users should install this update which addresses this
vulnerability, fixes these bugs and adds these enhancements. After
installing the updated packages, libvirtd must be restarted ("service
libvirtd restart") for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2511.html">CVE-2011-2511</cve>
                <bugzilla href="http://bugzilla.redhat.com/665075" id="665075">minor libvirt API break in error reporting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665549" id="665549">libvirt crash on src/util/util.c in __virExec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671569" id="671569">race condition in libvirt could lead to crash on event handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681623" id="681623">libvirt double-close bug in tight loop of save/restore [5.7]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689880" id="689880">guest with passthrough nic got kernel panic when send system_reset signal in QEMU monitor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690459" id="690459">rpmbuild failed on xencapstest when running under xen kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697749" id="697749">Deadlock between VM ops and filter update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703193" id="703193">support enabling/disabling xen hpet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/710151" id="710151">Auditing of QEMU driver disk hotunplug events logs is missing and/or incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/717199" id="717199">CVE-2011-2511 libvirt: integer overflow in VirDomainGetVcpus</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111019006" comment="libvirt-devel is earlier than 0:0.8.2-22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391005" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111019002" comment="libvirt is earlier than 0:0.8.2-22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391003" comment="libvirt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111019004" comment="libvirt-python is earlier than 0:0.8.2-22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391007" comment="libvirt-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111065" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1065: Red Hat Enterprise Linux 5.7 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1065-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1065.html" />
          <reference source="CVE" ref_id="CVE-2011-1780" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1780.html" />
          <reference source="CVE" ref_id="CVE-2011-2525" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2525.html" />
          <reference source="CVE" ref_id="CVE-2011-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2689.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A flaw was found in the way the Xen hypervisor implementation handled
instruction emulation during virtual machine exits. A malicious user-space
process running in an SMP guest could trick the emulator into reading a
different instruction than the one that caused the virtual machine to exit.
An unprivileged guest user could trigger this flaw to crash the host. This
only affects systems with both an AMD x86 processor and the AMD
Virtualization (AMD-V) extensions enabled. (CVE-2011-1780, Important)

* A flaw allowed the tc_fill_qdisc() function in the Linux kernel's packet
scheduler API implementation to be called on built-in qdisc structures. A
local, unprivileged user could use this flaw to trigger a NULL pointer
dereference, resulting in a denial of service. (CVE-2011-2525, Moderate)

* A flaw was found in the way space was allocated in the Linux kernel's
Global File System 2 (GFS2) implementation. If the file system was almost
full, and a local, unprivileged user made an fallocate() request, it could
result in a denial of service. Note: Setting quotas to prevent users from
using all available disk space would prevent exploitation of this flaw.
(CVE-2011-2689, Moderate)

These updated kernel packages include a number of bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Refer to the Red Hat Enterprise Linux 5.7 Technical Notes for
information about the most significant bug fixes and enhancements included
in this update:

https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/5.7_Technical_Notes/kernel.html#RHSA-2011-1065

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1780.html">CVE-2011-1780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2525.html">CVE-2011-2525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2689.html">CVE-2011-2689</cve>
                <bugzilla href="http://bugzilla.redhat.com/390451" id="390451">Pick up paging performance improvements from upstream Xen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431738" id="431738">lsattr doesn't show attributes of ext3 quota files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441730" id="441730">[rhts] connectathon nfsidem test failing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452650" id="452650">[RHEL5.2]: Blktap is limited to 100 disks total</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460821" id="460821">pv-on-hvm: disk shows up twice.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465876" id="465876">NMI Watchdog detected LOCKUP in :sctp:sctp_copy_local_addr_list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477032" id="477032">kdump hang on HP xw9400</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481546" id="481546">HTB qdisc miscalculates bandwidth with TSO enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481629" id="481629">update myri10g driver from 1.3.2 to 1.5.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491740" id="491740">export of an NFSV3 file system via kerberos requires AUTH_SYS as well</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491786" id="491786">s2io should check inputs for rx_ring_sz</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494927" id="494927">Read-only filesystem after 'ext3_free_blocks_sb: bit already cleared for block' errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501314" id="501314">No beep when running xen kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511901" id="511901">[NFS]: silly renamed .nfs0000* files can be left on fs forever</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517629" id="517629">Sequence id issue with nfs4/kerberos between RHEL kernel and Fedora 11</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525898" id="525898">soft lockups with kswapd in RHEL 5.4 kernel 2.6.18-164.el5 x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537277" id="537277">KERNEL: QLA2XXX 0000:0E:00.0: RISC PAUSED -- HCCR=0, DUMPING FIRMWARE!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/553411" id="553411">xts crypto module missing from RHEL5 installer runtime</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/553803" id="553803">GFS2: recovery stuck on transaction lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567449" id="567449">RHEL5.6: iw_cxgb4 driver inclusion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/567540" id="567540">unregister_netdevice: waiting for veth5 to become free when I remove netloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/579000" id="579000">[RFE] Support L2 packets under bonding layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/579858" id="579858">Wrong RX bytes/packet count on vlan interface with igb driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/589512" id="589512">slab corruption after seeing some nfs-related BUG: warning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/603345" id="603345">i5k_amb does not work for Intel 5000 Chipset (kernel)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/607114" id="607114">System panic in pskb_expand_head When arp_validate option is specified in bonding ARP monitor mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/611407" id="611407">kvm guest unable to kdump without noapic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/621916" id="621916">Host panic on cross-vendor migration (RHEL 5.5 guest)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622542" id="622542">Xorg failures on machines using intel video card driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/622647" id="622647">Reading /proc/locks yelds corrupt data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/623979" id="623979">synch arch/i386/pci/irq-xen.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626585" id="626585">GFS2: [RFE] fallocate support for GFS2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626974" id="626974">nfs: too many GETATTR and ACCESS calls after direct i/o</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/626977" id="626977">[nfs] make close(2) asynchronous when closing nfs o_direct files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/627496" id="627496">Fix shrinking windows with window scaling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/631950" id="631950">remove FS-Cache code from NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/632399" id="632399">Misleading message from fs/nfs/file.c:do_vfs_lock()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/633196" id="633196">testing NMI watchdog ... &lt;4>WARNING: CPU#0: NMI appears to be stuck (62->62)!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/635992" id="635992">Areca driver, arcmsr,  update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/637970" id="637970">GFS2: Not enough space reserved in gfs2_write_begin and possibly elsewhere.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/642388" id="642388">ip_nat_ftp not working if ack for "227 Enter Passive mode" packet is lost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643292" id="643292">[netfront] ethtool -i should return proper information for netfront device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/643872" id="643872">[netback] ethtool -i should return proper information for netback device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645343" id="645343">ISCSI/multipath hang - must propagate SCSI device deletion to DM mpath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645528" id="645528">SIGPROF keeps a large task from ever completing a fork()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/645646" id="645646">RFE: Virtio nic should be support "ethtool -i virtio nic"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/646513" id="646513">HP_GETHOSTINFO ioctl always causes mpt controller reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648572" id="648572">virtio GSO makes IPv6 very slow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648657" id="648657">fseek()/NFS performance regression between RHEL4 and RHEL5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/648854" id="648854">linux-2.6.18: netback: take net_schedule_list_lock when removing entry from net_schedule_list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651333" id="651333">RHEL5.6: EHCI: AMD periodic frame list table quirk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651409" id="651409">BAD SEQID error messages returned by the NFS server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/651512" id="651512">e1000 driver tracebacks when running under VMware ESX4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652321" id="652321">jbd2_stats_proc_init has wrong location.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/652369" id="652369">temporary loss of path to SAN results in persistent EIO with msync</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653286" id="653286">[5.6][REG]for some uses of 'nfsservctl' system call, the kernel crashes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/653828" id="653828">bonding failover in every monitor interval with virtio-net driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/654293" id="654293">sunrpc: need a better way to set tcp_slot_table_entries in RHEL 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/656836" id="656836">Memory leak in virtio-console driver if driver probe routine fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/657166" id="657166">XFS causes kernel panic due to double free of log tickets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658012" id="658012">NMI panic during xfs forced shutdown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/658418" id="658418">Kernel warning at boot:  i7core_edac: probe of 0000:80:14.0 failed with error -22</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659594" id="659594">Kernel panic when restart network on vlan with bonding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659715" id="659715">cifs: ia64 kernel unaligned access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/659816" id="659816">Performance counters don't work on HP Magnycours machines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660368" id="660368">dm-crypt: backport changes to support xts crypto mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660661" id="660661">fsck.gfs2 reported statfs error after gfs2_grow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660728" id="660728">[LSI 5.7 feat] Update megaraid_sas to 5.34 and Include "Thunderbolt" support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/660871" id="660871">mpctl module doesn't release fasync_struct at file close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661300" id="661300">xfstest 222: filesystem on /dev/loop0 is inconsistent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661306" id="661306">[Cisco 5.7 FEAT] Update enic driver to version 2.1.1.9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/661904" id="661904">GFS2: Kernel changes necessary to allow growing completely full filesystems.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663041" id="663041">gfs2 FIEMAP oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663123" id="663123">/proc/partitions not updating after creating LUNs via hpacucli</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663563" id="663563">[ext4/xfstests] 011 caused filesystem corruption after running many times in a loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664592" id="664592">a test unit ready causes a panic on 5.6 (CCISS driver)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/664931" id="664931">COW corruption using popen(3).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665197" id="665197">WARNING: APIC timer calibration may be wrong</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/665972" id="665972">ISVM bit (ECX:31) for CPUID 0x00000001 is missing for HVM on AMD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666080" id="666080">GFS2: Blocks not marked free on delete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666304" id="666304">scsi_dh_emc gives "error attaching hardware handler" for EMC active-active SANs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/666866" id="666866">Heavy load on ath5k wireless device makes system unresponsive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667327" id="667327">lib: fix vscnprintf() if @size is == 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667660" id="667660">[NetApp 5.7 Bug] Include new NetApp PID entry to the alua_dev_list array in the ALUA hardware handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/667810" id="667810">"modprobe ip_conntrack hashsize=NNNN" panics kernel if /etc/modprobe.conf has hashsize=MMMM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/668934" id="668934">UDP transmit under VLAN causes guest freeze</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669603" id="669603">incomplete local port reservation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/669961" id="669961">[NetApp 5.6 Bug] Erroneous TPG ID check in SCSI ALUA Handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670367" id="670367">scsi_dh_emc get_req function should set REQ_FAILFAST flags same as upstream and other modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/670373" id="670373">panic in kfree() due to race condition in acpi_bus_receive_event()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671238" id="671238">[bonding]  crash when adding/removing slaves with master interface down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/671595" id="671595">Flapping errors (and panic) with bonding and arp_interval while using be2net included in 2.6.18-238</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672619" id="672619">transmission stops when tap does not consume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672724" id="672724">mmapping a read only file on a gfs2 filesystem incorrectly acquires an exclusive glock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/672981" id="672981">lseek() over NFS is returning an incorrect file length under some circumstances</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673058" id="673058">kernel panic in pg_init_done - pgpath already deleted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673242" id="673242">Time runs too fast in a VM on processors with > 4GHZ freq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673459" id="673459">virtio_console driver never returns from selecting for write when the queue is full</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/673616" id="673616">vdso gettimeofday causes a segmentation fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674175" id="674175">Impossible to load sctp module with ipv6 disable=1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674226" id="674226">Panic in selinux_bprm_post_apply_creds() due to an empty tty_files list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674298" id="674298">[NetApp 5.6 Bug] QLogic 8G FC firmware dumps seen during IO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/674514" id="674514">xenctx shows nonsensical values for 32-on-64 and HVM domains</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675727" id="675727">vdso: missing wall_to_monotomic export</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/675986" id="675986">Fix block based fiemap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677703" id="677703">[RHEL5.5] Panic in iscsi_sw_tcp_data_ready()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677893" id="677893">[TestOnly] gfs regression testing for 5.7 beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/677902" id="677902">Incorrect "Speed" is recorded in the file "/proc/net/bonding/bondX"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678073" id="678073">qeth: allow channel path changes in recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678074" id="678074">[usb-audio] unable to set capture mixer levels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678359" id="678359">online disk resizing may cause data corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678571" id="678571">hap_gva_to_gfn_* do not preserve domain context</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/678618" id="678618">gdbsx hypervisor part backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679120" id="679120">qeth: remove needless IPA-commands in offline</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679407" id="679407">[5.7] niu: Fix races between up/down and get_stats.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/679487" id="679487">[5.7] net: Fix netdev_run_todo serialization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/680329" id="680329">sunrpc: reconnect race can lead to socket read corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681303" id="681303">backport vzalloc and vzalloc_node in support of drivers needing these functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/681586" id="681586">Out of vmalloc space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683155" id="683155">gfs2: creating large files suddenly slow to a crawl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/683978" id="683978">need to backport common vpd infrastructure to rhel 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/684795" id="684795">missed unlock_page() in gfs2_write_begin()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688646" id="688646">intel_iommu domain id exhaustion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688989" id="688989">[5.6] sysctl tcp_syn_retries is not honored</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689860" id="689860">guest with passthrough nic got kernel panic when send system_reset signal in QEMU monitor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689943" id="689943">GFS2 causes kernel panic in spectator mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690555" id="690555">GFS2: resource group bitmap corruption resulting in panics and withdraws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/692946" id="692946">need to backport debugfs_remove_recursive functionality</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695357" id="695357">dasd: fix race between open and offline</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/696411" id="696411">Missing patch for full use of tcp_rto_min parameter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698432" id="698432">[Emulex 5.7] Update lpfc driver to version 8.2.0.96.1p</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698879" id="698879">The pci resource for vf is not released after hot-removing Intel 82576 NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/700546" id="700546">RHEL5: apparent file system corruption of snapshot fs with qla2xxx driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/702355" id="702355">NFS: Fix build break with CONFIG_NFS_V4=n</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/702652" id="702652">provide option to disable HPET</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/702657" id="702657">CVE-2011-1780 kernel: xen: svm: insufficiencies in handling emulated instructions during vm exits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703213" id="703213">GFS2: Add "dlm callback owed" glock flag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703416" id="703416">host kernel panic while guest running  on 10G public bridge.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/704497" id="704497">VT-d: Fix resource leaks on error paths in intremap code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/705324" id="705324">cifs: regression in unicode conversion routines when mounting with -o mapchars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/705455" id="705455">intel-iommu: missing flush prior to removing domains + avoid broken vm/si domain unlinking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/705725" id="705725">hvm guest time may go backwards on some hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706414" id="706414">Adding slave to balance-tlb bond device results in soft lockup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/709224" id="709224">setfacl does not update ctime when changing file permission on ext3/4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711450" id="711450">12% degradation running IOzone with Outcache testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/717068" id="717068">Kernel panics during Veritas SF testing.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/717742" id="717742">[RHEL5.7][kernel-xen] HVM guests hang during installation on AMD systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720552" id="720552">CVE-2011-2525 kernel: kernel: net_sched: fix qdisc_notify()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720861" id="720861">CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065004" comment="kernel-headers is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065002" comment="kernel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065024" comment="kernel-doc is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065020" comment="kernel-PAE-devel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065014" comment="kernel-devel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065006" comment="kernel-debug is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065016" comment="kernel-kdump is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065008" comment="kernel-xen-devel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065012" comment="kernel-debug-devel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065022" comment="kernel-PAE is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065018" comment="kernel-kdump-devel is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111065010" comment="kernel-xen is earlier than 0:2.6.18-274.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111073" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1073: bash security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1073-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1073.html" />
          <reference source="CVE" ref_id="CVE-2008-5374" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5374.html" />
    
    <description>Bash is the default shell for Red Hat Enterprise Linux.

It was found that certain scripts bundled with the Bash documentation
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files accessible to the victim running the
scripts. (CVE-2008-5374)

This update fixes the following bugs:

* When using the source builtin at location ".", occasionally, bash
opted to preserve internal consistency and abort scripts. This caused
bash to abort scripts that assigned values to read-only variables.
This is now fixed to ensure that such scripts are now executed as
written and not aborted. (BZ#448508)

* When the tab key was pressed for auto-completion options for the typed
text, the cursor moved to an unexpected position on a previous line if
the prompt contained characters that cannot be viewed and a "\]". This
is now fixed to retain the cursor at the expected position at the end of
the target line after autocomplete options correctly display. (BZ#463880)

* Bash attempted to interpret the NOBITS .dynamic section of the ELF
header. This resulted in a "^D: bad ELF interpreter: No such
file or directory" message. This is fixed to ensure that the invalid
"^D" does not appear in the error message. (BZ#484809)

* The $RANDOM variable in Bash carried over values from a previous
execution for later jobs. This is fixed and the $RANDOM variable
generates a new random number for each use. (BZ#492908)

* When Bash ran a shell script with an embedded null character, bash's
source builtin parsed the script incorrectly. This is fixed and
bash's source builtin correctly parses shell script null characters.
(BZ#503701)

* The bash manual page for "trap" did not mention that signals ignored upon
entry cannot be listed later. The manual page was updated for this update
and now specifically notes that "Signals ignored upon entry to the shell
cannot be trapped, reset or listed". (BZ#504904)

* Bash's readline incorrectly displayed additional text when resizing
the terminal window when text spanned more than one line, which caused
incorrect display output. This is now fixed to ensure that text in more
than one line in a resized window displays as expected. (BZ#525474)

* Previously, bash incorrectly displayed "Broken pipe" messages for
builtins like "echo" and "printf" when output did not succeed due to
EPIPE. This is fixed to ensure that the unnecessary "Broken pipe"
messages no longer display. (BZ#546529)

* Inserts with the repeat function were not possible after a deletion in
vi-mode. This has been corrected and, with this update, the repeat function
works as expected after a deletion. (BZ#575076)

* In some situations, bash incorrectly appended "/" to files instead of
just directories during tab-completion, causing incorrect
auto-completions. This is fixed and auto-complete appends "/" only to
directories. (BZ#583919)

* Bash had a memory leak in the "read" builtin when the number of fields
being read was not equal to the number of variables passed as arguments,
causing a shell script crash. This is fixed to prevent a memory leak and
shell script crash. (BZ#618393)

* /usr/share/doc/bash-3.2/loadables in the bash package contained source
files which would not build due to missing C header files. With this
update, the unusable (and unbuildable) source files were removed from the
package. (BZ#663656)

This update also adds the following enhancement:

* The system-wide "/etc/bash.bash_logout" bash logout file is now enabled.
This allows administrators to write system-wide logout actions for all
users. (BZ#592979)

Users of bash are advised to upgrade to this updated package, which
contains backported patches to resolve these issues and add this
enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5374.html">CVE-2008-5374</cve>
                <bugzilla href="http://bugzilla.redhat.com/448508" id="448508">Parsing of {} broken; breaks startup scripts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463880" id="463880">bash completion in UTF8 locale has cursor positioning errors with long $PS1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475474" id="475474">CVE-2008-5374 bash: Insecure temporary file use in aliasconv.sh, aliasconv.bash, cshtobash (symlink attack)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484809" id="484809">[RHEL5] bash includes Control-D in "bad ELF interpreter" message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492908" id="492908">$RANDOM value remains the same</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503701" id="503701">Cannot process scripts beyond an embedded NULL character when running in 'source' mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504904" id="504904">trap -p not displaying ignored signal when run from child bash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525474" id="525474">bash/readline not detecting window resize properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/583919" id="583919">tab-completion appends slash to non-directories</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/592979" id="592979">system global bash.bash_logout is diabled in config-top.h</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/618393" id="618393">memory leak in bash reading files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/663656" id="663656">Unusable loadables in /doc</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111073002" comment="bash is earlier than 0:3.2-32.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111073003" comment="bash is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111083" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1083: fuse security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1083-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1083.html" />
          <reference source="CVE" ref_id="CVE-2010-3879" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3879.html" />
          <reference source="CVE" ref_id="CVE-2011-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0541.html" />
          <reference source="CVE" ref_id="CVE-2011-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0542.html" />
          <reference source="CVE" ref_id="CVE-2011-0543" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0543.html" />
    
    <description>FUSE (Filesystem in Userspace) can implement a fully functional file system
in a user-space program. These packages provide the mount utility,
fusermount, the tool used to mount FUSE file systems.

Multiple flaws were found in the way fusermount handled the mounting and
unmounting of directories when symbolic links were present. A local user in
the fuse group could use these flaws to unmount file systems, which they
would otherwise not be able to unmount and that were not mounted using
FUSE, via a symbolic link attack. (CVE-2010-3879, CVE-2011-0541,
CVE-2011-0542, CVE-2011-0543)

Note: The util-linux-ng RHBA-2011:0699 update must also be installed to
fully correct the above flaws.

All users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-20" />
        <updated date="2011-07-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-3879.html">CVE-2010-3879</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0541.html">CVE-2011-0541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0542.html">CVE-2011-0542</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0543.html">CVE-2011-0543</cve>
                <bugzilla href="http://bugzilla.redhat.com/651183" id="651183">CVE-2010-3879 CVE-2011-0541 CVE-2011-0542 CVE-2011-0543 fuse: unprivileged user can unmount arbitrary locations via symlink attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111083009" comment="fuse-libs is earlier than 0:2.8.3-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111083010" comment="fuse-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111083005" comment="fuse is earlier than 0:2.8.3-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111083006" comment="fuse is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111083007" comment="fuse-devel is earlier than 0:2.8.3-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111083008" comment="fuse-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111084" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1084: libsndfile security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1084-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1084.html" />
          <reference source="CVE" ref_id="CVE-2011-2696" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2696.html" />
    
    <description>The libsndfile packages provide a library for reading and writing sound
files.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the libsndfile library processed certain Ensoniq PARIS
Audio Format (PAF) audio files. An attacker could create a
specially-crafted PAF file that, when opened, could cause an application
using libsndfile to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-2696)

Users of libsndfile are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
using libsndfile must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-20" />
        <updated date="2011-07-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2696.html">CVE-2011-2696</cve>
                <bugzilla href="http://bugzilla.redhat.com/721234" id="721234">CVE-2011-2696 libsndfile: Application crash due integer overflow by processing certain PAF audio files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111084005" comment="libsndfile is earlier than 0:1.0.20-3.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111084006" comment="libsndfile is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111084007" comment="libsndfile-devel is earlier than 0:1.0.20-3.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111084008" comment="libsndfile-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111085" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1085: freetype security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1085-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1085.html" />
          <reference source="CVE" ref_id="CVE-2011-0226" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0226.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

A flaw was found in the way the FreeType font rendering engine processed
certain PostScript Type 1 fonts. If a user loaded a specially-crafted font
file with an application linked against FreeType, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-0226)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-21" />
        <updated date="2011-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0226.html">CVE-2011-0226</cve>
                <bugzilla href="http://bugzilla.redhat.com/722701" id="722701">CVE-2011-0226 freetype: postscript type1 font parsing vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111085005" comment="freetype is earlier than 0:2.3.11-6.el6_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085006" comment="freetype is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111085007" comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085008" comment="freetype-demos is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111085009" comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085010" comment="freetype-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111087" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1087-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1087.html" />
          <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html" />
          <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
          <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2011-0802, CVE-2011-0814,
CVE-2011-0862, CVE-2011-0865, CVE-2011-0867, CVE-2011-0871, CVE-2011-0873)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR12-FP5 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-22" />
        <updated date="2011-07-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0802.html">CVE-2011-0802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0814.html">CVE-2011-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0873.html">CVE-2011-0873</cve>
                <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711675" id="711675">CVE-2011-0873 Oracle/IBM JDK: unspecified vulnerability fixed in 6u26 (2D)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711677" id="711677">CVE-2011-0802 CVE-2011-0814 Oracle/IBM JDK: unspecified vulnerabilities fixed in 6u26 (Sound)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087010" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169009" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087006" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169005" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087016" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169007" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087004" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087012" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169017" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087008" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087014" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169011" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087030" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169035" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087022" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169023" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087024" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169031" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087032" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169027" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087026" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169029" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087034" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169033" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111087028" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169025" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111088" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1088: systemtap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1088-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1088.html" />
          <reference source="CVE" ref_id="CVE-2011-2502" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2502.html" />
          <reference source="CVE" ref_id="CVE-2011-2503" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2503.html" />
    
    <description>SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

It was found that SystemTap did not perform proper module path sanity
checking if a user specified a custom path to the uprobes module, used
when performing user-space probing ("staprun -u"). A local user who is a
member of the stapusr group could use this flaw to bypass intended
module-loading restrictions, allowing them to escalate their privileges by
loading an arbitrary, unsigned module. (CVE-2011-2502)

A race condition flaw was found in the way the staprun utility performed
module loading. A local user who is a member of the stapusr group could
use this flaw to modify a signed module while it is being loaded,
allowing them to escalate their privileges. (CVE-2011-2503)

SystemTap users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-25" />
        <updated date="2011-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2502.html">CVE-2011-2502</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2503.html">CVE-2011-2503</cve>
                <bugzilla href="http://bugzilla.redhat.com/716476" id="716476">CVE-2011-2502 systemtap: insufficient security check when loading uprobes kernel module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716489" id="716489">CVE-2011-2503 systemtap: signed module loading race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088015" comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842020" comment="systemtap-runtime is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088013" comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842018" comment="systemtap-testsuite is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088009" comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842010" comment="systemtap-grapher is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088005" comment="systemtap is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842006" comment="systemtap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088017" comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842008" comment="systemtap-sdt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088007" comment="systemtap-client is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842016" comment="systemtap-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088011" comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842014" comment="systemtap-initscript is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111088019" comment="systemtap-server is earlier than 0:1.4-6.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110842012" comment="systemtap-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111089" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1089: systemtap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1089-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1089.html" />
          <reference source="CVE" ref_id="CVE-2011-2503" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2503.html" />
    
    <description>SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

A race condition flaw was found in the way the staprun utility performed
module loading. A local user who is a member of the stapusr group could use
this flaw to modify a signed module while it is being loaded, allowing them
to escalate their privileges. (CVE-2011-2503)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-25" />
        <updated date="2011-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2503.html">CVE-2011-2503</cve>
                <bugzilla href="http://bugzilla.redhat.com/716489" id="716489">CVE-2011-2503 systemtap: signed module loading race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089012" comment="systemtap-testsuite is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841011" comment="systemtap-testsuite is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089006" comment="systemtap-runtime is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841007" comment="systemtap-runtime is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089002" comment="systemtap is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841003" comment="systemtap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089014" comment="systemtap-sdt-devel is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841009" comment="systemtap-sdt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089004" comment="systemtap-client is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841013" comment="systemtap-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089008" comment="systemtap-initscript is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841005" comment="systemtap-initscript is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111089010" comment="systemtap-server is earlier than 0:1.3-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110841015" comment="systemtap-server is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111100" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1100: icedtea-web security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1100.html" />
          <reference source="CVE" ref_id="CVE-2011-2513" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2513.html" />
          <reference source="CVE" ref_id="CVE-2011-2514" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2514.html" />
    
    <description>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

A flaw was discovered in the JNLP (Java Network Launching Protocol)
implementation in IcedTea-Web. An unsigned Java Web Start application
could use this flaw to manipulate the content of a Security Warning
dialog box, to trick a user into granting the application unintended access
permissions to local files. (CVE-2011-2514)

An information disclosure flaw was discovered in the JNLP implementation in
IcedTea-Web. An unsigned Java Web Start application or Java applet could
use this flaw to determine the path to the cache directory used to store
downloaded Java class and archive files, and therefore determine the user's
login name. (CVE-2011-2513)

All icedtea-web users should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-27" />
        <updated date="2011-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2513.html">CVE-2011-2513</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2514.html">CVE-2011-2514</cve>
                <bugzilla href="http://bugzilla.redhat.com/718164" id="718164">CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/718170" id="718170">CVE-2011-2514 icedtea-web: Java Web Start security warning dialog manipulation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111100007" comment="icedtea-web-javadoc is earlier than 0:1.0.4-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111100008" comment="icedtea-web-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111100005" comment="icedtea-web is earlier than 0:1.0.4-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111100006" comment="icedtea-web is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111102" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1102: libsoup security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1102.html" />
          <reference source="CVE" ref_id="CVE-2011-2524" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2524.html" />
    
    <description>libsoup is an HTTP client/library implementation for GNOME.

A directory traversal flaw was found in libsoup's SoupServer. If an
application used SoupServer to implement an HTTP service, a remote attacker
who is able to connect to that service could use this flaw to access any
local files accessible to that application via a specially-crafted request.
(CVE-2011-2524)

All users of libsoup should upgrade to these updated packages, which
contain a backported patch to resolve this issue. All running applications
using libsoup's SoupServer must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-28" />
        <updated date="2011-07-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2524.html">CVE-2011-2524</cve>
                <bugzilla href="http://bugzilla.redhat.com/720509" id="720509">CVE-2011-2524 libsoup: SoupServer directory traversal flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111102007" comment="libsoup-devel is earlier than 0:2.28.2-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111102008" comment="libsoup-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111102005" comment="libsoup is earlier than 0:2.28.2-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111102006" comment="libsoup is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111103" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1103: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1103.html" />
          <reference source="CVE" ref_id="CVE-2011-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2692.html" />
    
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain a backported patch to correct this issue. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-28" />
        <updated date="2011-07-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2692.html">CVE-2011-2692</cve>
                <bugzilla href="http://bugzilla.redhat.com/720612" id="720612">CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111103002" comment="libpng is earlier than 2:1.2.7-8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111103003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111103004" comment="libpng-devel is earlier than 2:1.2.7-8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111103005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111103008" comment="libpng10-devel is earlier than 0:1.0.16-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111103009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111103006" comment="libpng10 is earlier than 0:1.0.16-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111103007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111104" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1104: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1104.html" />
          <reference source="CVE" ref_id="CVE-2011-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2690.html" />
          <reference source="CVE" ref_id="CVE-2011-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2692.html" />
    
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A buffer overflow flaw was found in the way libpng processed certain PNG
image files. An attacker could create a specially-crafted PNG image that,
when opened, could cause an application using libpng to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-2690)

Note: The application behavior required to exploit CVE-2011-2690 is rarely
used. No application shipped with Red Hat Enterprise Linux behaves this
way, for example.

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
libpng must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-28" />
        <updated date="2011-07-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2690.html">CVE-2011-2690</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2692.html">CVE-2011-2692</cve>
                <bugzilla href="http://bugzilla.redhat.com/720607" id="720607">CVE-2011-2690 libpng: buffer overwrite in png_rgb_to_gray</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720612" id="720612">CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks</bugzilla>
        <affected_cpe_list>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111104002" comment="libpng is earlier than 2:1.2.10-7.1.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111104003" comment="libpng is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111104004" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111104005" comment="libpng-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111105" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1105: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1105.html" />
          <reference source="CVE" ref_id="CVE-2011-2501" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2501.html" />
          <reference source="CVE" ref_id="CVE-2011-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2690.html" />
          <reference source="CVE" ref_id="CVE-2011-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2692.html" />
    
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A buffer overflow flaw was found in the way libpng processed certain PNG
image files. An attacker could create a specially-crafted PNG image that,
when opened, could cause an application using libpng to crash or,
potentially, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-2690)

Note: The application behavior required to exploit CVE-2011-2690 is rarely
used. No application shipped with Red Hat Enterprise Linux behaves this
way, for example.

An out-of-bounds memory read flaw was found in the way libpng processed
certain PNG image files. An attacker could create a specially-crafted PNG
image that, when opened, could cause an application using libpng to crash.
(CVE-2011-2501)

An uninitialized memory read issue was found in the way libpng processed
certain PNG images that use the Physical Scale (sCAL) extension. An
attacker could create a specially-crafted PNG image that, when opened,
could cause an application using libpng to crash. (CVE-2011-2692)

Users of libpng should upgrade to these updated packages, which upgrade
libpng to version 1.2.46 to correct these issues. All running applications
using libpng must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-07-28" />
        <updated date="2011-07-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2501.html">CVE-2011-2501</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2690.html">CVE-2011-2690</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2692.html">CVE-2011-2692</cve>
                <bugzilla href="http://bugzilla.redhat.com/717084" id="717084">CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720607" id="720607">CVE-2011-2690 libpng: buffer overwrite in png_rgb_to_gray</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720612" id="720612">CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111105007" comment="libpng-static is earlier than 2:1.2.46-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111105008" comment="libpng-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111105005" comment="libpng is earlier than 2:1.2.46-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111105006" comment="libpng is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111105009" comment="libpng-devel is earlier than 2:1.2.46-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111105010" comment="libpng-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111109" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1109: foomatic security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1109.html" />
          <reference source="CVE" ref_id="CVE-2011-2697" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2697.html" />
    
    <description>Foomatic is a comprehensive, spooler-independent database of printers,
printer drivers, and driver descriptions. The package also includes
spooler-independent command line interfaces to manipulate queues and to
print files and manipulate print jobs. foomatic-rip is a print filter
written in Perl.

An input sanitization flaw was found in the foomatic-rip print filter. An
attacker could submit a print job with the username, title, or job options
set to appear as a command line option that caused the filter to use a
specified PostScript printer description (PPD) file, rather than the
administrator-set one. This could lead to arbitrary code execution with the
privileges of the "lp" user. (CVE-2011-2697)

All foomatic users should upgrade to this updated package, which contains
a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-01" />
        <updated date="2011-08-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2697.html">CVE-2011-2697</cve>
                <bugzilla href="http://bugzilla.redhat.com/721001" id="721001">CVE-2011-2697 foomatic: Improper sanitization of command line option in foomatic-rip</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111109002" comment="foomatic is earlier than 0:3.0.2-3.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111109003" comment="foomatic is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111109005" comment="foomatic is earlier than 0:3.0.2-38.3.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111109006" comment="foomatic is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111110" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1110: foomatic security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1110.html" />
          <reference source="CVE" ref_id="CVE-2011-2964" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2964.html" />
    
    <description>Foomatic is a comprehensive, spooler-independent database of printers,
printer drivers, and driver descriptions. The package also includes
spooler-independent command line interfaces to manipulate queues and to
print files and manipulate print jobs. foomatic-rip is a print filter
written in C.

An input sanitization flaw was found in the foomatic-rip print filter. An
attacker could submit a print job with the username, title, or job options
set to appear as a command line option that caused the filter to use a
specified PostScript printer description (PPD) file, rather than the
administrator-set one. This could lead to arbitrary code execution with the
privileges of the "lp" user. (CVE-2011-2964)

All foomatic users should upgrade to this updated package, which contains
a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-01" />
        <updated date="2011-08-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2964.html">CVE-2011-2964</cve>
                <bugzilla href="http://bugzilla.redhat.com/727016" id="727016">CVE-2011-2964 foomatic: Improper sanitization of command line option in foomatic-rip (foomatic.c)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111110005" comment="foomatic is earlier than 0:4.0.4-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111110006" comment="foomatic is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111132" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1132: dbus security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1132.html" />
          <reference source="CVE" ref_id="CVE-2011-2200" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2200.html" />
    
    <description>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial of service flaw was found in the way the D-Bus library handled
endianness conversion when receiving messages. A local user could use this
flaw to send a specially-crafted message to dbus-daemon or to a service
using the bus, such as Avahi or NetworkManager, possibly causing the
daemon to exit or the service to disconnect from the bus. (CVE-2011-2200)

All users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. For the update to take effect, all
running instances of dbus-daemon and all running applications using the
libdbus library must be restarted, or the system rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-09" />
        <updated date="2011-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2200.html">CVE-2011-2200</cve>
                <bugzilla href="http://bugzilla.redhat.com/712676" id="712676">CVE-2011-2200 dbus: Local DoS via messages with non-native byte order</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132008" comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376005" comment="dbus-x11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132006" comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376009" comment="dbus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132002" comment="dbus is earlier than 0:1.1.2-16.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376003" comment="dbus is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132004" comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376007" comment="dbus-libs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132020" comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376019" comment="dbus-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132018" comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376023" comment="dbus-x11 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132022" comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376017" comment="dbus-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132014" comment="dbus is earlier than 1:1.2.24-5.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376015" comment="dbus is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111132016" comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110376021" comment="dbus-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111144" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1144: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1144.html" />
          <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html" />
          <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html" />
          <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html" />
          <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html" />
          <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html" />
          <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html" />
          <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html" />
          <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html" />
          <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html" />
          <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html" />
          <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html" />
          <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html" />
          <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html" />
          <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed on the Adobe security page APSB11-21, listed
in the References section.

Multiple security flaws were found in the way flash-plugin displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
potentially, execute arbitrary code when the victim loaded a page
containing the specially-crafted SWF content. (CVE-2011-2130,
CVE-2011-2134, CVE-2011-2135, CVE-2011-2136, CVE-2011-2137, CVE-2011-2138,
CVE-2011-2139, CVE-2011-2140, CVE-2011-2414, CVE-2011-2415, CVE-2011-2416,
CVE-2011-2417, CVE-2011-2425)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.183.5.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-10" />
        <updated date="2011-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2130.html">CVE-2011-2130</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2134.html">CVE-2011-2134</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2135.html">CVE-2011-2135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2136.html">CVE-2011-2136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2137.html">CVE-2011-2137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2138.html">CVE-2011-2138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2139.html">CVE-2011-2139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2140.html">CVE-2011-2140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2414.html">CVE-2011-2414</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2415.html">CVE-2011-2415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2416.html">CVE-2011-2416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2417.html">CVE-2011-2417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2424.html">CVE-2011-2424</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2425.html">CVE-2011-2425</cve>
                <bugzilla href="http://bugzilla.redhat.com/729497" id="729497">CVE-2011-2130 CVE-2011-2134 CVE-2011-2135 CVE-2011-2136 CVE-2011-2137 CVE-2011-2138 CVE-2011-2139 CVE-2011-2140 CVE-2011-2414 CVE-2011-2415 CVE-2011-2416 CVE-2011-2417 CVE-2011-2425 flash-plugin: multiple arbitrary code execution flaws (APSB-11-21)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111144002" comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111144008" comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111154" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1154: libXfont security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1154.html" />
          <reference source="CVE" ref_id="CVE-2011-2895" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2895.html" />
    
    <description>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A buffer overflow flaw was found in the way the libXfont library, used by
the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to potentially
execute arbitrary code with the privileges of the X.Org server.
(CVE-2011-2895)

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-11" />
        <updated date="2011-08-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2895.html">CVE-2011-2895</cve>
                <bugzilla href="http://bugzilla.redhat.com/725760" id="725760">CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/727624" id="727624">CVE-2011-2895 BSD compress LZW decoder buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111154002" comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111154003" comment="libXfont is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111154004" comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111154005" comment="libXfont-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111154010" comment="libXfont is earlier than 0:1.4.1-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111154011" comment="libXfont is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111154012" comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111154013" comment="libXfont-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111155" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1155: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1155-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1155.html" />
          <reference source="CVE" ref_id="CVE-2011-2895" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2895.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon. These xorg-x11 packages also provide the
X.Org libXfont runtime library.

A buffer overflow flaw was found in the way the libXfont library, used by
the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to potentially
execute arbitrary code with the privileges of the X.Org server.
(CVE-2011-2895)

Users of xorg-x11 should upgrade to these updated packages, which contain
a backported patch to resolve this issue. All running X.Org server
instances must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-11" />
        <updated date="2011-08-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2895.html">CVE-2011-2895</cve>
                <bugzilla href="http://bugzilla.redhat.com/725760" id="725760">CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/727624" id="727624">CVE-2011-2895 BSD compress LZW decoder buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155012" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155008" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432037" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155024" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432033" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155020" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432017" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155016" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432027" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155010" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432021" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155004" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432023" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155006" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155034" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432025" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155028" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432011" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432035" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155022" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432005" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155018" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432007" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155014" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432019" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155036" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432009" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155032" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432029" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111155030" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.69" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432031" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111159" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1159: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1159-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1159.html" />
          <reference source="CVE" ref_id="CVE-2011-0311" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0311.html" />
          <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html" />
          <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html" />
          <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html" />
          <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html" />
          <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html" />
          <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html" />
          <reference source="CVE" ref_id="CVE-2011-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3387.html" />
    
    <description>The IBM 1.4.2 SR13-FP10 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2011-0311, CVE-2011-0802,
CVE-2011-0814, CVE-2011-0862, CVE-2011-0865, CVE-2011-0867, CVE-2011-0871)

Note: The RHSA-2011:0490 java-1.4.2-ibm update did not, unlike the erratum
text stated, provide a complete fix for the CVE-2011-0311 issue.

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP10 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-15" />
        <updated date="2011-08-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0311.html">CVE-2011-0311</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0802.html">CVE-2011-0802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0814.html">CVE-2011-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0862.html">CVE-2011-0862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0865.html">CVE-2011-0865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0867.html">CVE-2011-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0871.html">CVE-2011-0871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3387.html">CVE-2011-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/702349" id="702349">CVE-2011-0311 IBM JDK Class file parsing denial-of-service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706106" id="706106">CVE-2011-0865 OpenJDK: Deserialization allows creation of mutable SignedObject (Deserialization, 6618658)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706139" id="706139">CVE-2011-0862 OpenJDK: integer overflows in JPEGImageReader and font SunLayoutEngine (2D, 7013519)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706153" id="706153">CVE-2011-0867 OpenJDK: NetworkInterface information leak (Networking, 7013969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/706248" id="706248">CVE-2011-0871 OpenJDK: MediaTracker created Component instances with unnecessary privileges (Swing, 7020198)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/711677" id="711677">CVE-2011-0802 CVE-2011-0814 Oracle/IBM JDK: unspecified vulnerabilities fixed in 6u26 (Sound)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159012" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159008" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159010" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111159004" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.10-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110152009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111160" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1160: dhcp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1160.html" />
          <reference source="CVE" ref_id="CVE-2011-2748" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2748.html" />
          <reference source="CVE" ref_id="CVE-2011-2749" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2749.html" />
    
    <description>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

Two denial of service flaws were found in the way the dhcpd daemon handled
certain incomplete request packets. A remote attacker could use these flaws
to crash dhcpd via a specially-crafted request. (CVE-2011-2748,
CVE-2011-2749)

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing this update, all
DHCP servers will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-15" />
        <updated date="2011-08-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2748.html">CVE-2011-2748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2749.html">CVE-2011-2749</cve>
                <bugzilla href="http://bugzilla.redhat.com/729382" id="729382">CVE-2011-2748 CVE-2011-2749 dhcp: denial of service flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160006" comment="dhcp-devel is earlier than 7:3.0.1-68.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428026" comment="dhcp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160004" comment="dhclient is earlier than 7:3.0.1-68.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428028" comment="dhclient is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160002" comment="dhcp is earlier than 7:3.0.1-68.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428024" comment="dhcp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160015" comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428009" comment="libdhcp4client-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160017" comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428011" comment="dhclient is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160013" comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428007" comment="dhcp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160009" comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428003" comment="dhcp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160011" comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110428005" comment="libdhcp4client is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160027" comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256010" comment="dhclient is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160025" comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256008" comment="dhcp-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111160023" comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110256006" comment="dhcp is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111161" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1161: freetype security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1161-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1161.html" />
          <reference source="CVE" ref_id="CVE-2011-2895" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2895.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2 font
engines.

A buffer overflow flaw was found in the way the FreeType library handled
malformed font files compressed using UNIX compress. If a user loaded a
specially-crafted compressed font file with an application linked against
FreeType, it could cause the application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2011-2895)

Note: This issue only affects the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue. The X server must be restarted (log
out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-15" />
        <updated date="2011-08-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2895.html">CVE-2011-2895</cve>
                <bugzilla href="http://bugzilla.redhat.com/727624" id="727624">CVE-2011-2895 BSD compress LZW decoder buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111161004" comment="freetype-utils is earlier than 0:2.1.9-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161005" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111161002" comment="freetype is earlier than 0:2.1.9-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111161006" comment="freetype-demos is earlier than 0:2.1.9-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161007" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111161008" comment="freetype-devel is earlier than 0:2.1.9-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161009" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111164" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1164: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1164.html" />
          <reference source="CVE" ref_id="CVE-2011-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0084.html" />
          <reference source="CVE" ref_id="CVE-2011-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2378.html" />
          <reference source="CVE" ref_id="CVE-2011-2981" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2981.html" />
          <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html" />
          <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html" />
          <reference source="CVE" ref_id="CVE-2011-2984" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2984.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2982)

A dangling pointer flaw was found in the Firefox Scalable Vector Graphics
(SVG) text manipulation routine. A web page containing a malicious SVG
image could cause Firefox to crash or, potentially, execute arbitrary code
with the privileges of the user running Firefox. (CVE-2011-0084)

A dangling pointer flaw was found in the way Firefox handled a certain
Document Object Model (DOM) element. A web page containing malicious
content could cause Firefox to crash or, potentially, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2011-2378)

A flaw was found in the event management code in Firefox. A website
containing malicious JavaScript could cause Firefox to execute that
JavaScript with the privileges of the user running Firefox. (CVE-2011-2981)

A flaw was found in the way Firefox handled malformed JavaScript. A web
page containing malicious JavaScript could cause Firefox to access already
freed memory, causing Firefox to crash or, potentially, execute arbitrary
code with the privileges of the user running Firefox. (CVE-2011-2983)

It was found that a malicious web page could execute arbitrary code with
the privileges of the user running Firefox if the user dropped a tab onto
the malicious web page. (CVE-2011-2984)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.20. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.20, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-16" />
        <updated date="2011-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0084.html">CVE-2011-0084</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2378.html">CVE-2011-2378</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2981.html">CVE-2011-2981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2982.html">CVE-2011-2982</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2983.html">CVE-2011-2983</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2984.html">CVE-2011-2984</cve>
                <bugzilla href="http://bugzilla.redhat.com/730518" id="730518">CVE-2011-2982 Mozilla: Miscellaneous memory safety hazards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730519" id="730519">CVE-2011-0084 Mozilla: Crash in SVGTextElement.getCharNumAtPosition()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730520" id="730520">CVE-2011-2981 Mozilla: Privilege escalation using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730521" id="730521">CVE-2011-2378 Mozilla: Dangling pointer vulnerability in appendChild</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730522" id="730522">CVE-2011-2984 Mozilla: Privilege escalation dropping a tab element in content area</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730523" id="730523">CVE-2011-2983 Mozilla: Private data leakage using RegExp.input</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164002" comment="xulrunner is earlier than 0:1.9.2.20-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164004" comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164006" comment="firefox is earlier than 0:3.6.20-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111164009" comment="firefox is earlier than 0:3.6.20-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164015" comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164017" comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111164019" comment="firefox is earlier than 0:3.6.20-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111165" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1165: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1165.html" />
          <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html" />
          <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2011-2982)

A flaw was found in the way Thunderbird handled malformed JavaScript.
Malicious content could cause Thunderbird to access already freed memory,
causing Thunderbird to crash or, potentially, execute arbitrary code with
the privileges of the user running Thunderbird. (CVE-2011-2983)

Note: This update disables support for Scalable Vector Graphics (SVG)
images in Thunderbird on Red Hat Enterprise Linux 5.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-16" />
        <updated date="2011-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2982.html">CVE-2011-2982</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2983.html">CVE-2011-2983</cve>
                <bugzilla href="http://bugzilla.redhat.com/730518" id="730518">CVE-2011-2982 Mozilla: Miscellaneous memory safety hazards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730523" id="730523">CVE-2011-2983 Mozilla: Private data leakage using RegExp.input</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111165002" comment="thunderbird is earlier than 0:2.0.0.24-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111165005" comment="thunderbird is earlier than 0:1.5.0.12-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111166" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1166: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1166-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1166.html" />
          <reference source="CVE" ref_id="CVE-2011-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0084.html" />
          <reference source="CVE" ref_id="CVE-2011-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2378.html" />
          <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2982)

A dangling pointer flaw was found in the Thunderbird Scalable Vector
Graphics (SVG) text manipulation routine. An HTML mail message containing a
malicious SVG image could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-0084)

A dangling pointer flaw was found in the way Thunderbird handled a certain
Document Object Model (DOM) element. An HTML mail message containing
malicious content could cause Thunderbird to crash or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-2378)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-16" />
        <updated date="2011-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0084.html">CVE-2011-0084</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2378.html">CVE-2011-2378</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2982.html">CVE-2011-2982</cve>
                <bugzilla href="http://bugzilla.redhat.com/730518" id="730518">CVE-2011-2982 Mozilla: Miscellaneous memory safety hazards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730519" id="730519">CVE-2011-0084 Mozilla: Crash in SVGTextElement.getCharNumAtPosition()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730521" id="730521">CVE-2011-2378 Mozilla: Dangling pointer vulnerability in appendChild</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111166005" comment="thunderbird is earlier than 0:3.1.12-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111167" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1167: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1167-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1167.html" />
          <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html" />
          <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2011-2982)

A flaw was found in the way SeaMonkey handled malformed JavaScript. A web
page containing malicious JavaScript could cause SeaMonkey to access
already freed memory, causing SeaMonkey to crash or, potentially, execute
arbitrary code with the privileges of the user running SeaMonkey.
(CVE-2011-2983)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-16" />
        <updated date="2011-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2982.html">CVE-2011-2982</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2983.html">CVE-2011-2983</cve>
                <bugzilla href="http://bugzilla.redhat.com/730518" id="730518">CVE-2011-2982 Mozilla: Miscellaneous memory safety hazards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730523" id="730523">CVE-2011-2983 Mozilla: Private data leakage using RegExp.input</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167006" comment="seamonkey-mail is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167002" comment="seamonkey is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167008" comment="seamonkey-devel is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167004" comment="seamonkey-chat is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111167010" comment="seamonkey-js-debugger is earlier than 0:1.0.9-72.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111187" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1187: dovecot security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1187-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1187.html" />
          <reference source="CVE" ref_id="CVE-2011-1929" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1929.html" />
    
    <description>Dovecot is an IMAP server for Linux, UNIX, and similar operating systems,
primarily written with security in mind.

A denial of service flaw was found in the way Dovecot handled NULL
characters in certain header names. A mail message with specially-crafted
headers could cause the Dovecot child process handling the target user's
connection to crash, blocking them from downloading the message
successfully and possibly leading to the corruption of their mailbox.
(CVE-2011-1929)

Users of dovecot are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages, the dovecot service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-18" />
        <updated date="2011-08-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1929.html">CVE-2011-1929</cve>
                <bugzilla href="http://bugzilla.redhat.com/706286" id="706286">CVE-2011-1929 dovecot: potential crash when parsing header names that contain NUL characters</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111187002" comment="dovecot is earlier than 0:0.99.11-10.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111187003" comment="dovecot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111187005" comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111187006" comment="dovecot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111187019" comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600014" comment="dovecot-pigeonhole is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111187015" comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600010" comment="dovecot-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111187011" comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600006" comment="dovecot is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111187017" comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600012" comment="dovecot-pgsql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111187013" comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110600008" comment="dovecot-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111189" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1189: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1189-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1189.html" />
          <reference source="CVE" ref_id="CVE-2011-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1182.html" />
          <reference source="CVE" ref_id="CVE-2011-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1576.html" />
          <reference source="CVE" ref_id="CVE-2011-1593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1593.html" />
          <reference source="CVE" ref_id="CVE-2011-1776" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1776.html" />
          <reference source="CVE" ref_id="CVE-2011-1898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1898.html" />
          <reference source="CVE" ref_id="CVE-2011-2183" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2183.html" />
          <reference source="CVE" ref_id="CVE-2011-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2213.html" />
          <reference source="CVE" ref_id="CVE-2011-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2491.html" />
          <reference source="CVE" ref_id="CVE-2011-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2492.html" />
          <reference source="CVE" ref_id="CVE-2011-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2495.html" />
          <reference source="CVE" ref_id="CVE-2011-2497" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2497.html" />
          <reference source="CVE" ref_id="CVE-2011-2517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2517.html" />
          <reference source="CVE" ref_id="CVE-2011-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2689.html" />
          <reference source="CVE" ref_id="CVE-2011-2695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2695.html" />
    
    <description>Security issues:

* Using PCI passthrough without interrupt remapping support allowed KVM
guests to generate MSI interrupts and thus potentially inject traps. A
privileged guest user could use this flaw to crash the host or possibly
escalate their privileges on the host. The fix for this issue can prevent
PCI passthrough working and guests starting. Refer to Red Hat Bugzilla bug
715555 for details. (CVE-2011-1898, Important)

* Flaw in the client-side NLM implementation could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-2491, Important)

* Integer underflow in the Bluetooth implementation could allow a remote
attacker to cause a denial of service or escalate their privileges by
sending a specially-crafted request to a target system via Bluetooth.
(CVE-2011-2497, Important)

* Buffer overflows in the netlink-based wireless configuration interface
implementation could allow a local user, who has the CAP_NET_ADMIN
capability, to cause a denial of service or escalate their privileges on
systems that have an active wireless interface. (CVE-2011-2517, Important)

* Flaw in the way the maximum file offset was handled for ext4 file systems
could allow a local, unprivileged user to cause a denial of service.
(CVE-2011-2695, Important)

* Flaw allowed napi_reuse_skb() to be called on VLAN packets. An attacker
on the local network could use this flaw to send crafted packets to a
target, possibly causing a denial of service. (CVE-2011-1576, Moderate)

* Integer signedness error in next_pidmap() could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-1593, Moderate)

* Race condition in the memory merging support (KSM) could allow a local,
unprivileged user to cause a denial of service. KSM is off by default, but
on systems running VDSM, or on KVM hosts, it is likely turned on by the
ksm/ksmtuned services. (CVE-2011-2183, Moderate)

* Flaw in inet_diag_bc_audit() could allow a local, unprivileged user to
cause a denial of service. (CVE-2011-2213, Moderate)

* Flaw in the way space was allocated in the Global File System 2 (GFS2)
implementation. If the file system was almost full, and a local,
unprivileged user made an fallocate() request, it could result in a denial
of service. Setting quotas to prevent users from using all available disk
space would prevent exploitation of this flaw. (CVE-2011-2689, Moderate)

* Local, unprivileged users could send signals via the sigqueueinfo system
call, with si_code set to SI_TKILL and with spoofed process and user IDs,
to other processes. This flaw does not allow existing permission checks to
be bypassed; signals can only be sent if your privileges allow you to
already do so. (CVE-2011-1182, Low)

* Heap overflow in the EFI GUID Partition Table (GPT) implementation could
allow a local attacker to cause a denial of service by mounting a disk
containing crafted partition tables. (CVE-2011-1776, Low)

* Structure padding in two structures in the Bluetooth implementation was
not initialized properly before being copied to user-space, possibly
allowing local, unprivileged users to leak kernel stack memory to
user-space. (CVE-2011-2492, Low)

* /proc/[PID]/io is world-readable by default. Previously, these files
could be read without any further restrictions. A local, unprivileged user
could read these files, belonging to other, possibly privileged processes
to gather confidential information, such as the length of a password used
in a process. (CVE-2011-2495, Low)

Red Hat would like to thank Vasily Averin for reporting CVE-2011-2491; Dan
Rosenberg for reporting CVE-2011-2497 and CVE-2011-2213; Ryan Sweat for
reporting CVE-2011-1576; Robert Swiecki for reporting CVE-2011-1593; Andrea
Righi for reporting CVE-2011-2183; Julien Tinnes of the Google Security
Team for reporting CVE-2011-1182; Timo Warns for reporting CVE-2011-1776;
Marek Kroemeke and Filip Palian for reporting CVE-2011-2492; and Vasiliy
Kulikov of Openwall for reporting CVE-2011-2495.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-23" />
        <updated date="2011-08-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1182.html">CVE-2011-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1576.html">CVE-2011-1576</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1593.html">CVE-2011-1593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1776.html">CVE-2011-1776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1898.html">CVE-2011-1898</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2183.html">CVE-2011-2183</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2213.html">CVE-2011-2213</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2491.html">CVE-2011-2491</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2492.html">CVE-2011-2492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2495.html">CVE-2011-2495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2497.html">CVE-2011-2497</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2517.html">CVE-2011-2517</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2689.html">CVE-2011-2689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2695.html">CVE-2011-2695</cve>
                <bugzilla href="http://bugzilla.redhat.com/690028" id="690028">CVE-2011-1182 kernel signal spoofing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695173" id="695173">CVE-2011-1576 kernel: net: Fix memory leak/corruption on VLAN GRO_DROP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697822" id="697822">CVE-2011-1593 kernel: proc: signedness issue in next_pidmap()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703019" id="703019">CVE-2011-2492 kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/703026" id="703026">CVE-2011-1776 kernel: validate size of EFI GUID partition entries</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/709393" id="709393">CVE-2011-2491 kernel: rpc task leak after flock()ing  NFS share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/710338" id="710338">CVE-2011-2183 kernel: ksm: race between ksmd and exiting task</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/713827" id="713827">Parallel port issue in RHEL 6.0 server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714536" id="714536">CVE-2011-2213 kernel: inet_diag: insufficient validation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714982" id="714982">GFS2: Update to rhel6.1 broke dovecot writing to a gfs2 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/715555" id="715555">CVE-2011-1898 virt: VT-d (PCI passthrough) MSI trap injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716539" id="716539">bump domain memory limits [6.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716805" id="716805">CVE-2011-2497 kernel: bluetooth: buffer overflow in l2cap config request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716825" id="716825">CVE-2011-2495 kernel: /proc/PID/io infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/718152" id="718152">CVE-2011-2517 kernel: nl80211: missing check for valid SSID size in scan operations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/720861" id="720861">CVE-2011-2689 kernel: gfs2: make sure fallocate bytes is a multiple of blksize</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722557" id="722557">CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189025" comment="kernel-firmware is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189009" comment="kernel-headers is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189005" comment="kernel is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189023" comment="kernel-doc is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189011" comment="kernel-devel is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189015" comment="perf is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189013" comment="kernel-debug is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189021" comment="kernel-kdump is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189017" comment="kernel-debug-devel is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189019" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111189007" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.12.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111196" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1196: system-config-printer security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1196-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1196.html" />
          <reference source="CVE" ref_id="CVE-2011-2899" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2899.html" />
    
    <description>system-config-printer is a print queue configuration tool with a graphical
user interface.

It was found that system-config-printer did not properly sanitize NetBIOS
and workgroup names when searching for network printers. A remote attacker
could use this flaw to execute arbitrary code with the privileges of the
user running system-config-printer. (CVE-2011-2899)

All users of system-config-printer are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. Running
instances of system-config-printer must be restarted for this update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-23" />
        <updated date="2011-08-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2899.html">CVE-2011-2899</cve>
                <bugzilla href="http://bugzilla.redhat.com/728348" id="728348">CVE-2011-2899 system-config-printer: possible arbitrary code execution in pysmb.py due to improper escaping of hostnames</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111196002" comment="system-config-printer is earlier than 0:0.6.116.10-1.6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111196003" comment="system-config-printer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111196004" comment="system-config-printer-gui is earlier than 0:0.6.116.10-1.6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111196005" comment="system-config-printer-gui is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111196009" comment="system-config-printer-libs is earlier than 0:0.7.32.10-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111196010" comment="system-config-printer-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111196007" comment="system-config-printer is earlier than 0:0.7.32.10-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111196008" comment="system-config-printer is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111197" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1197: libvirt security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1197.html" />
          <reference source="CVE" ref_id="CVE-2011-2511" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2511.html" />
    
    <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remotely managing virtualized systems.

An integer overflow flaw was found in libvirtd's RPC call handling. An
attacker able to establish read-only connections to libvirtd could trigger
this flaw by calling virDomainGetVcpus() with specially-crafted parameters,
causing libvirtd to crash. (CVE-2011-2511)

This update also fixes the following bugs:

* Previously, when the "virsh vol-create-from" command was run on an LVM
(Logical Volume Manager) storage pool, performance of the command was very
low and the operation consumed an excessive amount of time. This bug has
been fixed in the virStorageVolCreateXMLFrom() function, and the
performance problem of the command no longer occurs.

* Due to a regression, libvirt used undocumented command line options,
instead of the recommended ones. Consequently, the qemu-img utility used an
invalid argument while creating an encrypted volume, and the process
eventually failed. With this update, the bug in the backing format of the
storage back end has been fixed, and encrypted volumes can now be created
as expected. (BZ#726617)

* Due to a bug in the qemuAuditDisk() function, hot unplug failures were
never audited, and a hot unplug success was audited as a failure. This bug
has been fixed, and auditing of disk hot unplug operations now works as
expected. (BZ#728516)

* Previously, when a debug process was being activated, the act of
preparing a debug message ended up with dereferencing a UUID (universally
unique identifier) prior to the NULL argument check. Consequently, an API
running the debug process sometimes terminated with a segmentation fault.
With this update, a patch has been provided to address this issue, and the
crashes no longer occur in the described scenario. (BZ#728546)

* The libvirt library uses the "boot=on" option to mark which disk is
bootable but it only uses that option if Qemu advertises its support. The
qemu-kvm utility in Red Hat Enterprise Linux 6.1 removed support for that
option and libvirt could not use it. As a consequence, when an IDE disk was
added as the second storage with a virtio disk being set up as the first
one by default, the operating system tried to boot from the IDE disk rather
than the virtio disk and either failed to boot with the "No bootable disk"
error message returned, or the system booted whatever operating system was
on the IDE disk. With this update, the boot configuration is translated
into bootindex, which provides control over which device is used for
booting a guest operating system, thus fixing this bug.

All users of libvirt are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, libvirtd must be restarted ("service libvirtd
restart") for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-23" />
        <updated date="2011-08-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2511.html">CVE-2011-2511</cve>
                <bugzilla href="http://bugzilla.redhat.com/717199" id="717199">CVE-2011-2511 libvirt: integer overflow in VirDomainGetVcpus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/726617" id="726617">libvirt regression with creating encrypted volume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728516" id="728516">Auditing of QEMU driver disk hotunplug events logs is missing and/or incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728546" id="728546">[libvirt] [logs] null dereference while preparing libvirt logs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111197009" comment="libvirt-devel is earlier than 0:0.8.7-18.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391015" comment="libvirt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111197005" comment="libvirt is earlier than 0:0.8.7-18.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391013" comment="libvirt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111197011" comment="libvirt-python is earlier than 0:0.8.7-18.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391019" comment="libvirt-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111197007" comment="libvirt-client is earlier than 0:0.8.7-18.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110391017" comment="libvirt-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111212" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1212: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1212-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1212.html" />
          <reference source="CVE" ref_id="CVE-2011-2482" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2482.html" />
          <reference source="CVE" ref_id="CVE-2011-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2491.html" />
          <reference source="CVE" ref_id="CVE-2011-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2495.html" />
          <reference source="CVE" ref_id="CVE-2011-2517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2517.html" />
          <reference source="CVE" ref_id="CVE-2011-2519" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2519.html" />
          <reference source="CVE" ref_id="CVE-2011-2901" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2901.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A NULL pointer dereference flaw was found in the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation. A remote attacker
could send a specially-crafted SCTP packet to a target system, resulting in
a denial of service. (CVE-2011-2482, Important)

* A flaw in the Linux kernel's client-side NFS Lock Manager (NLM)
implementation could allow a local, unprivileged user to cause a denial of
service. (CVE-2011-2491, Important)

* Buffer overflow flaws in the Linux kernel's netlink-based wireless
configuration interface implementation could allow a local user, who has
the CAP_NET_ADMIN capability, to cause a denial of service or escalate
their privileges on systems that have an active wireless interface.
(CVE-2011-2517, Important)

* A flaw was found in the way the Linux kernel's Xen hypervisor
implementation emulated the SAHF instruction. When using a
fully-virtualized guest on a host that does not use hardware assisted
paging (HAP), such as those running CPUs that do not have support for (or
those that have it disabled) Intel Extended Page Tables (EPT) or AMD
Virtualization (AMD-V) Rapid Virtualization Indexing (RVI), a privileged
guest user could trigger this flaw to cause the hypervisor to crash.
(CVE-2011-2519, Moderate)

* An off-by-one flaw was found in the __addr_ok() macro in the Linux
kernel's Xen hypervisor implementation when running on 64-bit systems. A
privileged guest user could trigger this flaw to cause the hypervisor to
crash. (CVE-2011-2901, Moderate)

* /proc/[PID]/io is world-readable by default. Previously, these files
could be read without any further restrictions. A local, unprivileged user
could read these files, belonging to other, possibly privileged processes
to gather confidential information, such as the length of a password used
in a process. (CVE-2011-2495, Low)

Red Hat would like to thank Vasily Averin for reporting CVE-2011-2491, and
Vasiliy Kulikov of Openwall for reporting CVE-2011-2495.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-06" />
        <updated date="2011-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2482.html">CVE-2011-2482</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2491.html">CVE-2011-2491</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2495.html">CVE-2011-2495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2517.html">CVE-2011-2517</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2519.html">CVE-2011-2519</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2901.html">CVE-2011-2901</cve>
                <bugzilla href="http://bugzilla.redhat.com/709393" id="709393">CVE-2011-2491 kernel: rpc task leak after flock()ing  NFS share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/712885" id="712885">RHEL6.1 32bit xen hvm guest crash randomly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/714867" id="714867">CVE-2011-2482 kernel: sctp dos</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716825" id="716825">CVE-2011-2495 kernel: /proc/PID/io infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/718152" id="718152">CVE-2011-2517 kernel: nl80211: missing check for valid SSID size in scan operations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/718882" id="718882">CVE-2011-2519 kernel: xen: x86_emulate: fix SAHF emulation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/727590" id="727590">[xfs] mis-sized O_DIRECT I/O results in hung task timeouts [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/727835" id="727835">xfs_error_report() oops when passed-in mp is NULL [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728042" id="728042">CVE-2011-2901 kernel: xen: off-by-one shift in x86_64 __addr_ok()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212004" comment="kernel-headers is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212002" comment="kernel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212024" comment="kernel-doc is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212020" comment="kernel-PAE-devel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212006" comment="kernel-devel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212012" comment="kernel-debug is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212016" comment="kernel-kdump is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212008" comment="kernel-xen-devel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212014" comment="kernel-debug-devel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212022" comment="kernel-PAE is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212018" comment="kernel-kdump-devel is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111212010" comment="kernel-xen is earlier than 0:2.6.18-274.3.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111219" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1219: samba security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1219.html" />
          <reference source="CVE" ref_id="CVE-2010-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0547.html" />
          <reference source="CVE" ref_id="CVE-2010-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0787.html" />
          <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html" />
          <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html" />
          <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html" />
          <reference source="CVE" ref_id="CVE-2011-3585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3585.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

A race condition flaw was found in the way the mount.cifs tool mounted CIFS
(Common Internet File System) shares. If mount.cifs had the setuid bit set,
a local attacker could conduct a symbolic link attack to trick mount.cifs
into mounting a share over an arbitrary directory they were otherwise not
allowed to mount to, possibly allowing them to escalate their privileges.
(CVE-2010-0787)

It was found that the mount.cifs tool did not properly handle share or
directory names containing a newline character. If mount.cifs had the
setuid bit set, a local attacker could corrupt the mtab (mounted file
systems table) file via a specially-crafted CIFS share mount request.
(CVE-2010-0547)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the samba packages distributed by Red Hat does not
have the setuid bit set. We recommend that administrators do not manually
set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522; the Debian Security Team for reporting CVE-2010-0787;
and Dan Rosenberg for reporting CVE-2011-1678. Upstream acknowledges
Nobuhiro Tsuji of NTT DATA Security Corporation as the original reporter of
CVE-2011-2694; Yoshihiro Ishikawa of LAC Co., Ltd. as the original reporter
of CVE-2011-2522; and the Debian Security Team acknowledges Ronald Volgers
as the original reporter of CVE-2010-0787.

Users of Samba are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-29" />
        <updated date="2011-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0547.html">CVE-2010-0547</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-0787.html">CVE-2010-0787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1678.html">CVE-2011-1678</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2522.html">CVE-2011-2522</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2694.html">CVE-2011-2694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3585.html">CVE-2011-3585</cve>
                <bugzilla href="http://bugzilla.redhat.com/562156" id="562156">CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/577277" id="577277">CVE-2010-0787 samba: Race condition by mount (mount.cifs) operations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/695925" id="695925">CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/721348" id="721348">CVE-2011-2522 samba (SWAT): Absent CSRF protection in various Samba web configuration formulars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722537" id="722537">CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219004" comment="samba-client is earlier than 0:3.0.33-0.34.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305048" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219006" comment="samba-common is earlier than 0:3.0.33-0.34.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305044" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219002" comment="samba is earlier than 0:3.0.33-0.34.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305042" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219008" comment="samba-swat is earlier than 0:3.0.33-0.34.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305046" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219013" comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305007" comment="libsmbclient is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219017" comment="samba-client is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219021" comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305005" comment="libsmbclient-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219019" comment="samba-common is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305011" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219011" comment="samba is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111219015" comment="samba-swat is earlier than 0:3.0.33-3.29.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305013" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111220" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1220: samba3x security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1220-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1220.html" />
          <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html" />
          <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html" />
          <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html" />
          <reference source="CVE" ref_id="CVE-2011-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2724.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

It was found that the fix for CVE-2010-0547, provided by the Samba rebase
in RHBA-2011:0054, was incomplete. The mount.cifs tool did not properly
handle share or directory names containing a newline character, allowing a
local attacker to corrupt the mtab (mounted file systems table) file via a
specially-crafted CIFS (Common Internet File System) share mount request,
if mount.cifs had the setuid bit set. (CVE-2011-2724)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the samba3x packages distributed by Red Hat does not
have the setuid bit set. We recommend that administrators do not manually
set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522, and Dan Rosenberg for reporting CVE-2011-1678. Upstream
acknowledges Nobuhiro Tsuji of NTT DATA Security Corporation as the
original reporter of CVE-2011-2694, and Yoshihiro Ishikawa of LAC Co., Ltd.
as the original reporter of CVE-2011-2522.

Users of Samba are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-29" />
        <updated date="2011-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1678.html">CVE-2011-1678</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2522.html">CVE-2011-2522</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2694.html">CVE-2011-2694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2724.html">CVE-2011-2724</cve>
                <bugzilla href="http://bugzilla.redhat.com/695925" id="695925">CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/721348" id="721348">CVE-2011-2522 samba (SWAT): Absent CSRF protection in various Samba web configuration formulars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722537" id="722537">CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/726691" id="726691">CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220008" comment="samba3x-swat is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306011" comment="samba3x-swat is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220016" comment="samba3x-client is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306007" comment="samba3x-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220014" comment="samba3x-doc is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306015" comment="samba3x-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220004" comment="samba3x-winbind is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306009" comment="samba3x-winbind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220002" comment="samba3x is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306003" comment="samba3x is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220006" comment="samba3x-winbind-devel is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306017" comment="samba3x-winbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220012" comment="samba3x-common is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306013" comment="samba3x-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111220010" comment="samba3x-domainjoin-gui is earlier than 0:3.5.4-0.83.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110306005" comment="samba3x-domainjoin-gui is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111221" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1221: samba and cifs-utils security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1221-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1221.html" />
          <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html" />
          <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html" />
          <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html" />
          <reference source="CVE" ref_id="CVE-2011-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2724.html" />
          <reference source="CVE" ref_id="CVE-2011-3585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3585.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information. The cifs-utils package contains utilities for mounting
and managing CIFS (Common Internet File System) shares.

A cross-site scripting (XSS) flaw was found in the password change page of
the Samba Web Administration Tool (SWAT). If a remote attacker could trick
a user, who was logged into the SWAT interface, into visiting a
specially-crafted URL, it would lead to arbitrary web script execution in
the context of the user's SWAT session. (CVE-2011-2694)

It was found that SWAT web pages did not protect against Cross-Site
Request Forgery (CSRF) attacks. If a remote attacker could trick a user,
who was logged into the SWAT interface, into visiting a specially-crafted
URL, the attacker could perform Samba configuration changes with the
privileges of the logged in user. (CVE-2011-2522)

It was found that the fix for CVE-2010-0547, provided in the cifs-utils
package included in the GA release of Red Hat Enterprise Linux 6, was
incomplete. The mount.cifs tool did not properly handle share or directory
names containing a newline character, allowing a local attacker to corrupt
the mtab (mounted file systems table) file via a specially-crafted CIFS
share mount request, if mount.cifs had the setuid bit set. (CVE-2011-2724)

It was found that the mount.cifs tool did not handle certain errors
correctly when updating the mtab file. If mount.cifs had the setuid bit
set, a local attacker could corrupt the mtab file by setting a small file
size limit before running mount.cifs. (CVE-2011-1678)

Note: mount.cifs from the cifs-utils package distributed by Red Hat does
not have the setuid bit set. We recommend that administrators do not
manually set the setuid bit for mount.cifs.

Red Hat would like to thank the Samba project for reporting CVE-2011-2694
and CVE-2011-2522, and Dan Rosenberg for reporting CVE-2011-1678. Upstream
acknowledges Nobuhiro Tsuji of NTT DATA Security Corporation as the
original reporter of CVE-2011-2694, and Yoshihiro Ishikawa of LAC Co., Ltd.
as the original reporter of CVE-2011-2522.

This update also fixes the following bug:

* If plain text passwords were used ("encrypt passwords = no" in
"/etc/samba/smb.conf"), Samba clients running the Windows XP or Windows
Server 2003 operating system may not have been able to access Samba shares
after installing the Microsoft Security Bulletin MS11-043. This update
corrects this issue, allowing such clients to use plain text passwords to
access Samba shares. (BZ#728517)

Users of samba and cifs-utils are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues. After
installing this update, the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-29" />
        <updated date="2011-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1678.html">CVE-2011-1678</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2522.html">CVE-2011-2522</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2694.html">CVE-2011-2694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2724.html">CVE-2011-2724</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3585.html">CVE-2011-3585</cve>
                <bugzilla href="http://bugzilla.redhat.com/695925" id="695925">CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/721348" id="721348">CVE-2011-2522 samba (SWAT): Absent CSRF protection in various Samba web configuration formulars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722537" id="722537">CVE-2011-2694 samba (SWAT): XSS flaw in Change Password page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/726691" id="726691">CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728517" id="728517">Windows security patch KB2536276 prevents access to samba shares</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221005" comment="cifs-utils is earlier than 0:4.8.1-2.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111221006" comment="cifs-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221013" comment="samba-domainjoin-gui is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305021" comment="samba-domainjoin-gui is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221023" comment="samba-winbind is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305033" comment="samba-winbind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221021" comment="libsmbclient is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305029" comment="libsmbclient is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221015" comment="samba-client is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305037" comment="samba-client is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221029" comment="samba-winbind-devel is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305025" comment="samba-winbind-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221027" comment="libsmbclient-devel is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305035" comment="libsmbclient-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221025" comment="samba-common is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305023" comment="samba-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221007" comment="samba is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305019" comment="samba is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221019" comment="samba-doc is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305031" comment="samba-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221011" comment="samba-winbind-clients is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305027" comment="samba-winbind-clients is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221017" comment="samba-winbind-krb5-locator is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111221018" comment="samba-winbind-krb5-locator is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111221009" comment="samba-swat is earlier than 0:3.5.6-86.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110305039" comment="samba-swat is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111240" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1240: Red Hat Enterprise Linux 4 - 6-Month End Of Life Notice (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1240-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1240.html" />
    
    <description>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
                <bugzilla href="http://bugzilla.redhat.com/732722" id="732722">Send Out RHEL 4 6-Month EOL Notice</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111240002" comment="redhat-release is earlier than 0:4AS-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111240004" comment="redhat-release is earlier than 0:4ES-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111240005" comment="redhat-release is earlier than 0:4WS-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111240006" comment="redhat-release is earlier than 0:4Desktop-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111241" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1241-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1241.html" />
          <reference source="CVE" ref_id="CVE-2011-1831" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1831.html" />
          <reference source="CVE" ref_id="CVE-2011-1832" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1832.html" />
          <reference source="CVE" ref_id="CVE-2011-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1834.html" />
          <reference source="CVE" ref_id="CVE-2011-1835" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1835.html" />
          <reference source="CVE" ref_id="CVE-2011-1837" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1837.html" />
          <reference source="CVE" ref_id="CVE-2011-3145" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3145.html" />
    
    <description>eCryptfs is a stacked, cryptographic file system. It is transparent to the
underlying file system and provides per-file granularity. eCryptfs is
released as a Technology Preview for Red Hat Enterprise Linux 5 and 6.

The setuid mount.ecryptfs_private utility allows users to mount an eCryptfs
file system. This utility can only be run by users in the "ecryptfs" group.

A race condition flaw was found in the way mount.ecryptfs_private checked
the permissions of a requested mount point when mounting an encrypted file
system. A local attacker could possibly use this flaw to escalate their
privileges by mounting over an arbitrary directory. (CVE-2011-1831)

A race condition flaw in umount.ecryptfs_private could allow a local
attacker to unmount an arbitrary file system. (CVE-2011-1832)

It was found that mount.ecryptfs_private did not handle certain errors
correctly when updating the mtab (mounted file systems table) file,
allowing a local attacker to corrupt the mtab file and possibly unmount an
arbitrary file system. (CVE-2011-1834)

An insecure temporary file use flaw was found in the ecryptfs-setup-private
script. A local attacker could use this script to insert their own key that
will subsequently be used by a new user, possibly giving the attacker
access to the user's encrypted data if existing file permissions allow
access. (CVE-2011-1835)

A race condition flaw in mount.ecryptfs_private could allow a local
attacker to overwrite arbitrary files. (CVE-2011-1837)

A race condition flaw in the way temporary files were accessed in
mount.ecryptfs_private could allow a malicious, local user to make
arbitrary modifications to the mtab file. (CVE-2011-3145)

A race condition flaw was found in the way mount.ecryptfs_private checked
the permissions of the directory to mount. A local attacker could use this
flaw to mount (and then access) a directory they would otherwise not have
access to. Note: The fix for this issue is incomplete until a kernel-space
change is made. Future Red Hat Enterprise Linux 5 and 6 kernel updates
will correct this issue. (CVE-2011-1833)

Red Hat would like to thank the Ubuntu Security Team for reporting these
issues. The Ubuntu Security Team acknowledges Vasiliy Kulikov of Openwall
and Dan Rosenberg as the original reporters of CVE-2011-1831,
CVE-2011-1832, and CVE-2011-1833; Dan Rosenberg and Marc Deslauriers as the
original reporters of CVE-2011-1834; Marc Deslauriers as the original
reporter of CVE-2011-1835; and Vasiliy Kulikov of Openwall as the original
reporter of CVE-2011-1837.

Users of ecryptfs-utils are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1831.html">CVE-2011-1831</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1832.html">CVE-2011-1832</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1834.html">CVE-2011-1834</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1835.html">CVE-2011-1835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1837.html">CVE-2011-1837</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3145.html">CVE-2011-3145</cve>
                <bugzilla href="http://bugzilla.redhat.com/729465" id="729465">CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/732607" id="732607">CVE-2011-3145 ecryptfs-utils: incorrect mtab group ownership</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241004" comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241005" comment="ecryptfs-utils-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241002" comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241003" comment="ecryptfs-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241006" comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241007" comment="ecryptfs-utils-gui is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241016" comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241017" comment="ecryptfs-utils-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241014" comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241015" comment="ecryptfs-utils-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111241012" comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111241013" comment="ecryptfs-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111242" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1242: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1242-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1242.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Firefox; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
                <bugzilla href="http://bugzilla.redhat.com/734316" id="734316">Fraudulent certificates signed by DigiNotar CA certificate (MFSA 2011-34)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111242002" comment="firefox is earlier than 0:3.6.20-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111242005" comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111242007" comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111242013" comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111242015" comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111243" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1243: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1243.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
                <bugzilla href="http://bugzilla.redhat.com/734316" id="734316">Fraudulent certificates signed by DigiNotar CA certificate (MFSA 2011-34)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111243002" comment="thunderbird is earlier than 0:2.0.0.24-24.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111243005" comment="thunderbird is earlier than 0:1.5.0.12-42.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111243011" comment="thunderbird is earlier than 0:3.1.12-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111244" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1244: seamonkey security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1244-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1244.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in SeaMonkey; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
                <bugzilla href="http://bugzilla.redhat.com/734316" id="734316">Fraudulent certificates signed by DigiNotar CA certificate (MFSA 2011-34)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244010" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244004" comment="seamonkey-mail is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244002" comment="seamonkey is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244008" comment="seamonkey-devel is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244006" comment="seamonkey-chat is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111244012" comment="seamonkey-js-debugger is earlier than 0:1.0.9-74.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111245" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1245: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1245.html" />
          <reference source="CVE" ref_id="CVE-2011-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3192.html" />
    
    <description>The Apache HTTP Server is a popular web server.

A flaw was found in the way the Apache HTTP Server handled Range HTTP
headers. A remote attacker could use this flaw to cause httpd to use an
excessive amount of memory and CPU time via HTTP requests with a
specially-crafted Range header. (CVE-2011-3192)

All httpd users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-08-31" />
        <updated date="2011-08-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3192.html">CVE-2011-3192</cve>
                <bugzilla href="http://bugzilla.redhat.com/732928" id="732928">CVE-2011-3192 httpd: multiple ranges DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245006" comment="httpd-manual is earlier than 0:2.0.52-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245007" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245010" comment="httpd-suexec is earlier than 0:2.0.52-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245004" comment="httpd-devel is earlier than 0:2.0.52-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245008" comment="mod_ssl is earlier than 0:2.0.52-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245009" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245002" comment="httpd is earlier than 0:2.0.52-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245015" comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245016" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245017" comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245018" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245019" comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245020" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245013" comment="httpd is earlier than 0:2.2.3-53.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245014" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245033" comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245034" comment="httpd-manual is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245031" comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245032" comment="httpd-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245027" comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245028" comment="httpd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245029" comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245030" comment="mod_ssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111245025" comment="httpd is earlier than 0:2.2.15-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245026" comment="httpd is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111247" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1247: rsyslog security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1247-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1247.html" />
          <reference source="CVE" ref_id="CVE-2011-3200" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3200.html" />
    
    <description>The rsyslog packages provide an enhanced, multi-threaded syslog daemon that
supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on
any message part, and fine grained output format control.

A two byte buffer overflow flaw was found in the rsyslog daemon's
parseLegacySyslogMsg function. An attacker able to submit log messages to
rsyslogd could use this flaw to crash the daemon. (CVE-2011-3200)

All rsyslog users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing this update, the
rsyslog daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-01" />
        <updated date="2011-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3200.html">CVE-2011-3200</cve>
                <bugzilla href="http://bugzilla.redhat.com/727644" id="727644">CVE-2011-3200 rsyslog: parseLegacySyslogMsg off-by-two buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247011" comment="rsyslog-gssapi is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247012" comment="rsyslog-gssapi is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247007" comment="rsyslog-pgsql is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247008" comment="rsyslog-pgsql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247005" comment="rsyslog is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247006" comment="rsyslog is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247013" comment="rsyslog-relp is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247014" comment="rsyslog-relp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247015" comment="rsyslog-gnutls is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247016" comment="rsyslog-gnutls is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111247009" comment="rsyslog-mysql is earlier than 0:4.6.2-3.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111247010" comment="rsyslog-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111248" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1248: ca-certificates security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1248-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1248.html" />
    
    <description>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update removes that CA's root certificate from the
ca-certificates package, rendering any HTTPS certificates signed by that CA
as untrusted. (BZ#734381)

All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-02" />
        <updated date="2011-09-02" />
                <bugzilla href="http://bugzilla.redhat.com/734381" id="734381">Remove DigiNotar CA cert from RHEL packages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111248005" comment="ca-certificates is earlier than 0:2010.63-3.el6_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111248006" comment="ca-certificates is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111264" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1264: gstreamer-plugins security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1264-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1264.html" />
          <reference source="CVE" ref_id="CVE-2011-2911" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2911.html" />
          <reference source="CVE" ref_id="CVE-2011-2912" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2912.html" />
          <reference source="CVE" ref_id="CVE-2011-2913" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2913.html" />
          <reference source="CVE" ref_id="CVE-2011-2914" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2914.html" />
          <reference source="CVE" ref_id="CVE-2011-2915" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2915.html" />
    
    <description>The gstreamer-plugins packages contain plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media formats.

An integer overflow flaw, a boundary error, and multiple off-by-one flaws
were found in various ModPlug music file format library (libmodplug)
modules, embedded in GStreamer. An attacker could create specially-crafted
music files that, when played by a victim, would cause applications using
GStreamer to crash or, potentially, execute arbitrary code. (CVE-2011-2911,
CVE-2011-2912, CVE-2011-2913, CVE-2011-2914, CVE-2011-2915)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as Rhythmbox)
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-06" />
        <updated date="2011-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2911.html">CVE-2011-2911</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2912.html">CVE-2011-2912</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2913.html">CVE-2011-2913</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2914.html">CVE-2011-2914</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2915.html">CVE-2011-2915</cve>
                <bugzilla href="http://bugzilla.redhat.com/728371" id="728371">CVE-2011-2911 CVE-2011-2912 CVE-2011-2913 CVE-2011-2914 CVE-2011-2915 libmodplug: multiple vulnerabilities reported in &lt;= 0.8.8.3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111264004" comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110477005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111264002" comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110477003" comment="gstreamer-plugins is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111266" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1266: seamonkey security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1266-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1266.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

The RHSA-2011:1244 SeaMonkey update rendered HTTPS certificates signed by a
certain Certificate Authority (CA) as untrusted, but made an exception for
a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-06" />
        <updated date="2011-09-06" />
                <bugzilla href="http://bugzilla.redhat.com/735483" id="735483">Additional certificates signed by DigiNotar CA certificate to be revoked (MFSA 2011-35)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266008" comment="seamonkey-mail is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266002" comment="seamonkey is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266004" comment="seamonkey-devel is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266010" comment="seamonkey-chat is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111266006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-75.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111267" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1267: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1267.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-06" />
        <updated date="2011-09-06" />
                <bugzilla href="http://bugzilla.redhat.com/735483" id="735483">Additional certificates signed by DigiNotar CA certificate to be revoked (MFSA 2011-35)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111267002" comment="thunderbird is earlier than 0:2.0.0.24-25.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111267005" comment="thunderbird is earlier than 0:1.5.0.12-43.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111267011" comment="thunderbird is earlier than 0:3.1.14-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111268" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1268: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1268-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1268.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

The RHSA-2011:1242 Firefox update rendered HTTPS certificates signed by a
certain Certificate Authority (CA) as untrusted, but made an exception for
a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.22. After installing the update, Firefox must be
restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-06" />
        <updated date="2011-09-06" />
                <bugzilla href="http://bugzilla.redhat.com/735483" id="735483">Additional certificates signed by DigiNotar CA certificate to be revoked (MFSA 2011-35)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111268002" comment="firefox is earlier than 0:3.6.22-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268005" comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268007" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268009" comment="firefox is earlier than 0:3.6.22-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268015" comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268017" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111268019" comment="firefox is earlier than 0:3.6.22-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111282" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1282: nss and nspr security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1282.html" />
    
    <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.

All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-12" />
        <updated date="2011-09-12" />
                <bugzilla href="http://bugzilla.redhat.com/734316" id="734316">Fraudulent certificates signed by DigiNotar CA certificate (MFSA 2011-34)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282004" comment="nspr-devel is earlier than 0:4.8.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111282005" comment="nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282002" comment="nspr is earlier than 0:4.8.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111282003" comment="nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282006" comment="nss is earlier than 0:3.12.10-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472026" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282010" comment="nss-tools is earlier than 0:3.12.10-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472030" comment="nss-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282008" comment="nss-devel is earlier than 0:3.12.10-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472028" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282015" comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111282016" comment="nspr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282013" comment="nspr is earlier than 0:4.8.8-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111282014" comment="nspr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282017" comment="nss is earlier than 0:3.12.10-4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472003" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282019" comment="nss-tools is earlier than 0:3.12.10-4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472009" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282023" comment="nss-devel is earlier than 0:3.12.10-4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472005" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282021" comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472007" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282033" comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472021" comment="nss-sysinit is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282029" comment="nss is earlier than 0:3.12.9-12.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472015" comment="nss is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282031" comment="nss-tools is earlier than 0:3.12.9-12.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472019" comment="nss-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282037" comment="nss-devel is earlier than 0:3.12.9-12.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472023" comment="nss-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111282035" comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472017" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111289" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1289: librsvg2 security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1289-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1289.html" />
      <reference source="CVE" ref_id="CVE-2011-3146" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3146.html" />
    <description>The librsvg2 packages provide an SVG (Scalable Vector Graphics) library
based on libart.

A flaw was found in the way librsvg2 parsed certain SVG files. An attacker
could create a specially-crafted SVG file that, when opened, would cause
applications that use librsvg2 (such as Eye of GNOME) to crash or,
potentially, execute arbitrary code. (CVE-2011-3146)

Red Hat would like to thank the Ubuntu Security Team for reporting this
issue. The Ubuntu Security Team acknowledges Sauli Pahlman as the original
reporter.

All librsvg2 users should upgrade to these updated packages, which contain
a backported patch to correct this issue. All running applications that use
librsvg2 must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-13" />
        <updated date="2011-09-13" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3146.html">CVE-2011-3146</cve>
        <bugzilla href="http://bugzilla.redhat.com/734936" id="734936">CVE-2011-3146 librsvg: object type mismatch leading to invalid pointer dereference</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111289005" comment="librsvg2 is earlier than 0:2.26.0-5.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111289006" comment="librsvg2 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111289007" comment="librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111289008" comment="librsvg2-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111293" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1293: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1293-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1293.html" />
          <reference source="CVE" ref_id="CVE-2011-3205" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3205.html" />
    
    <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A buffer overflow flaw was found in the way Squid parsed replies from
remote Gopher servers. A remote user allowed to send Gopher requests to a
Squid proxy could possibly use this flaw to cause the squid child process
to crash or execute arbitrary code with the privileges of the squid user,
by making Squid perform a request to an attacker-controlled Gopher server.
(CVE-2011-3205)

Users of squid should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing this update, the
squid service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-14" />
        <updated date="2011-09-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3205.html">CVE-2011-3205</cve>
                <bugzilla href="http://bugzilla.redhat.com/734583" id="734583">CVE-2011-3205 squid: buffer overflow flaw in Squid's Gopher reply parser (SQUID-2011:3)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111293005" comment="squid is earlier than 7:3.1.10-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110545006" comment="squid is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111317" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1317: cyrus-imapd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1317.html" />
          <reference source="CVE" ref_id="CVE-2011-3208" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3208.html" />
    
    <description>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

A buffer overflow flaw was found in the cyrus-imapd NNTP server, nntpd. A
remote user able to use the nntpd service could use this flaw to crash the
nntpd child process or, possibly, execute arbitrary code with the
privileges of the cyrus user. (CVE-2011-3208)

Red Hat would like to thank Greg Banks for reporting this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the update, cyrus-imapd will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-19" />
        <updated date="2011-09-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3208.html">CVE-2011-3208</cve>
                <bugzilla href="http://bugzilla.redhat.com/734926" id="734926">CVE-2011-3208 cyrus-imapd: nntpd buffer overflow in split_wildmats()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317010" comment="cyrus-imapd-murder is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859020" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317004" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859022" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317002" comment="cyrus-imapd is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859012" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317008" comment="cyrus-imapd-utils is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859014" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317006" comment="cyrus-imapd-devel is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859016" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317012" comment="perl-Cyrus is earlier than 0:2.2.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859018" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317019" comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859005" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317015" comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859003" comment="cyrus-imapd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317021" comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859009" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317017" comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859007" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317027" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859028" comment="cyrus-imapd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317031" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859032" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111317029" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859030" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111323" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1323: qt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1323.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
          <reference source="CVE" ref_id="CVE-2011-3194" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3194.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

A buffer overflow flaw was found in the way Qt handled certain gray-scale
image files. If a user loaded a specially-crafted gray-scale image file
with an application linked against Qt, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3194)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3194.html">CVE-2011-3194</cve>
                <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/733119" id="733119">CVE-2011-3194 qt buffer overflow in greyscale images</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323023" comment="qt-sqlite is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323024" comment="qt-sqlite is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323007" comment="qt-mysql is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323008" comment="qt-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323005" comment="qt is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323006" comment="qt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323013" comment="qt-odbc is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323014" comment="qt-odbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323019" comment="qt-demos is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323020" comment="qt-demos is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323021" comment="qt-doc is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323022" comment="qt-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323015" comment="qt-x11 is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323016" comment="qt-x11 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323009" comment="qt-devel is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323010" comment="qt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323025" comment="qt-postgresql is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323026" comment="qt-postgresql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323017" comment="phonon-backend-gstreamer is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323018" comment="phonon-backend-gstreamer is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111323011" comment="qt-examples is earlier than 1:4.6.2-17.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323012" comment="qt-examples is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111324" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1324: qt4 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1324.html" />
          <reference source="CVE" ref_id="CVE-2007-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0242.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
    
    <description>Qt 4 is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A flaw in the way Qt 4 expanded certain UTF-8 characters could be used to
prevent a Qt 4 based application from properly sanitizing user input.
Depending on the application, this could allow an attacker to perform
directory traversal, or for web applications, a cross-site scripting (XSS)
attack. (CVE-2007-0242)

A buffer overflow flaw was found in the harfbuzz module in Qt 4. If a user
loaded a specially-crafted font file with an application linked against Qt
4, it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

Users of Qt 4 should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt 4 libraries must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0242.html">CVE-2007-0242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
                <bugzilla href="http://bugzilla.redhat.com/234633" id="234633">CVE-2007-0242 QT UTF8 improper character expansion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324014" comment="qt4-odbc is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324015" comment="qt4-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324008" comment="qt4-devel is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324009" comment="qt4-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324010" comment="qt4-postgresql is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324011" comment="qt4-postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324002" comment="qt4 is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324003" comment="qt4 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324006" comment="qt4-sqlite is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324007" comment="qt4-sqlite is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324012" comment="qt4-mysql is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324013" comment="qt4-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111324004" comment="qt4-doc is earlier than 0:4.2.1-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111324005" comment="qt4-doc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111325" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1325: evolution28-pango security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1325.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
    
    <description>Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of evolution28-pango are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
                <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111325004" comment="evolution28-pango-devel is earlier than 0:1.14.9-13.el4_11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180018" comment="evolution28-pango-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111325002" comment="evolution28-pango is earlier than 0:1.14.9-13.el4_11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180016" comment="evolution28-pango is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111326" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1326: pango security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1326-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1326.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
    
    <description>Pango is a library used for the layout and rendering of internationalized
text.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in Pango. If a user loaded a specially-crafted font file with
an application that uses Pango, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of pango are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, you must restart your system or restart the X server for the update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
                <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111326004" comment="pango-devel is earlier than 0:1.14.9-8.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180005" comment="pango-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111326002" comment="pango is earlier than 0:1.14.9-8.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110180003" comment="pango is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111327" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1327: frysk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1327.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
    
    <description>frysk is an execution-analysis technology implemented using native Java and
C++. It provides developers and system administrators with the ability to
examine and analyze multi-host, multi-process, and multithreaded systems
while they are running. frysk is released as a Technology Preview for Red
Hat Enterprise Linux 4.

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping
engine used in the embedded Pango library. If a frysk application were used
to debug or trace a process that uses HarfBuzz while it loaded a
specially-crafted font file, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2011-3193)

Users of frysk are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running frysk
applications must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
                <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111327002" comment="frysk is earlier than 0:0.0.1.2007.08.03-8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111327003" comment="frysk is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111328" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1328: qt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1328-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1328.html" />
          <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html" />
          <reference source="CVE" ref_id="CVE-2011-3194" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3194.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System. HarfBuzz is an OpenType text shaping engine.

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user
loaded a specially-crafted font file with an application linked against Qt,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2011-3193)

A buffer overflow flaw was found in the way Qt handled certain gray-scale
image files. If a user loaded a specially-crafted gray-scale image file
with an application linked against Qt, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2011-3194)

Users of Qt should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications linked
against Qt libraries must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-21" />
        <updated date="2011-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3193.html">CVE-2011-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3194.html">CVE-2011-3194</cve>
                <bugzilla href="http://bugzilla.redhat.com/733118" id="733118">CVE-2011-3193 qt/harfbuzz buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/733119" id="733119">CVE-2011-3194 qt buffer overflow in greyscale images</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328019" comment="qt-sqlite is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323024" comment="qt-sqlite is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328015" comment="qt-mysql is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323008" comment="qt-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328005" comment="qt is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323006" comment="qt is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328017" comment="qt-odbc is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323014" comment="qt-odbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328013" comment="qt-demos is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323020" comment="qt-demos is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328021" comment="qt-x11 is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323016" comment="qt-x11 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328009" comment="qt-devel is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323010" comment="qt-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328007" comment="qt-doc is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323022" comment="qt-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328025" comment="qt-postgresql is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323026" comment="qt-postgresql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328023" comment="qt-examples is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323012" comment="qt-examples is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111328011" comment="phonon-backend-gstreamer is earlier than 1:4.6.2-20.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111323018" comment="phonon-backend-gstreamer is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111333" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1333: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
           <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1333-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1333.html" />
          <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html" />
          <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html" />
          <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html" />
          <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html" />
          <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html" />
          <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed on the Adobe security page APSB11-26, listed
in the References section.

Multiple security flaws were found in the way flash-plugin displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
potentially, execute arbitrary code when the victim loaded a page
containing the specially-crafted SWF content. (CVE-2011-2426,
CVE-2011-2427, CVE-2011-2428, CVE-2011-2430)

A flaw in flash-plugin could allow an attacker to conduct cross-site
scripting (XSS) attacks if a victim were tricked into visiting a
specially-crafted web page. (CVE-2011-2444)

This update also fixes an information disclosure flaw in flash-plugin.
(CVE-2011-2429)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.183.10.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-22" />
        <updated date="2011-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2426.html">CVE-2011-2426</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2427.html">CVE-2011-2427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2428.html">CVE-2011-2428</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2429.html">CVE-2011-2429</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2430.html">CVE-2011-2430</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2444.html">CVE-2011-2444</cve>
                <bugzilla href="http://bugzilla.redhat.com/740201" id="740201">CVE-2011-2444 flash-plugin: Cross-site scripting vulnerability fixed in APSB11-26</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740204" id="740204">CVE-2011-2429 flash-plugin: security control bypass information disclosure fixed in APSB11-26</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740388" id="740388">CVE-2011-2426 CVE-2011-2427 CVE-2011-2428 CVE-2011-2430 flash-plugin: critical flaws fixed in APSB11-26</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111333002" comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111333008" comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111338" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1338: NetworkManager security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1338-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1338.html" />
          <reference source="CVE" ref_id="CVE-2011-3364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3364.html" />
    
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times. The ifcfg-rh
NetworkManager plug-in is used in Red Hat Enterprise Linux distributions to
read and write configuration information from the
/etc/sysconfig/network-scripts/ifcfg-* files.

An input sanitization flaw was found in the way the ifcfg-rh NetworkManager
plug-in escaped network connection names containing special characters. If
PolicyKit was configured to allow local, unprivileged users to create and
save new network connections, they could create a connection with a
specially-crafted name, leading to the escalation of their privileges.
Note: By default, PolicyKit prevents unprivileged users from creating and
saving network connections. (CVE-2011-3364)

Red Hat would like to thank Matt McCutchen for reporting this issue.

Users of NetworkManager should upgrade to these updated packages, which
contain a backported patch to correct this issue. Running instances of
NetworkManager must be restarted ("service NetworkManager restart") for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-26" />
        <updated date="2011-09-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3364.html">CVE-2011-3364</cve>
                <bugzilla href="http://bugzilla.redhat.com/737338" id="737338">CVE-2011-3364 NetworkManager: Console user can escalate to root via newlines in ifcfg-rh connection name</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111338009" comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930010" comment="NetworkManager-glib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111338013" comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930008" comment="NetworkManager-gnome is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111338011" comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930014" comment="NetworkManager-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111338007" comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930012" comment="NetworkManager-glib-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111338005" comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110930006" comment="NetworkManager is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111341" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1341: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1341.html" />
          <reference source="CVE" ref_id="CVE-2011-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2372.html" />
          <reference source="CVE" ref_id="CVE-2011-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2995.html" />
          <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html" />
          <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html" />
          <reference source="CVE" ref_id="CVE-2011-3000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3000.html" />
    
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-2995)

A flaw was found in the way Firefox processed the "Enter" keypress event. A
malicious web page could present a download dialog while the key is
pressed, activating the default "Open" action. A remote attacker could
exploit this vulnerability by causing the browser to open malicious web
content. (CVE-2011-2372)

A flaw was found in the way Firefox handled Location headers in redirect
responses. Two copies of this header with different values could be a
symptom of a CRLF injection attack against a vulnerable server. Firefox now
treats two copies of the Location, Content-Length, or Content-Disposition
header as an error condition. (CVE-2011-3000)

A flaw was found in the way Firefox handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Firefox handled large
JavaScript regular expressions. A web page containing malicious JavaScript
could cause Firefox to access already freed memory, causing Firefox to
crash or, potentially, execute arbitrary code with the privileges of the
user running Firefox. (CVE-2011-2998)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.23. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.23, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-28" />
        <updated date="2011-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2372.html">CVE-2011-2372</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2995.html">CVE-2011-2995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2998.html">CVE-2011-2998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2999.html">CVE-2011-2999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3000.html">CVE-2011-3000</cve>
                <bugzilla href="http://bugzilla.redhat.com/741902" id="741902">CVE-2011-2995 Mozilla: Miscellaneous memory safety hazards  (MFSA 2011-36)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741904" id="741904">CVE-2011-2999 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741905" id="741905">CVE-2011-3000 Mozilla:Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741917" id="741917">CVE-2011-2372 Mozilla:Code installation through holding down Enter (MFSA 2011-40)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741924" id="741924">CVE-2011-2998 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111341002" comment="firefox is earlier than 0:3.6.23-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341005" comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341007" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341009" comment="firefox is earlier than 0:3.6.23-2.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341015" comment="firefox is earlier than 0:3.6.23-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341017" comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111341019" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111342" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1342: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1342-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1342.html" />
          <reference source="CVE" ref_id="CVE-2011-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2372.html" />
          <reference source="CVE" ref_id="CVE-2011-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2995.html" />
          <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html" />
          <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html" />
          <reference source="CVE" ref_id="CVE-2011-3000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3000.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML content. An
HTML mail message containing malicious content could cause Thunderbird to
crash or, potentially, execute arbitrary code with the privileges of the
user running Thunderbird. (CVE-2011-2995)

A flaw was found in the way Thunderbird processed the "Enter" keypress
event. A malicious HTML mail message could present a download dialog while
the key is pressed, activating the default "Open" action. A remote attacker
could exploit this vulnerability by causing the mail client to open
malicious web content. (CVE-2011-2372)

A flaw was found in the way Thunderbird handled Location headers in
redirect responses. Two copies of this header with different values could
be a symptom of a CRLF injection attack against a vulnerable server.
Thunderbird now treats two copies of the Location, Content-Length, or
Content-Disposition header as an error condition. (CVE-2011-3000)

A flaw was found in the way Thunderbird handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Thunderbird handled large
JavaScript regular expressions. An HTML mail message containing malicious
JavaScript could cause Thunderbird to access already freed memory, causing
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-2998)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-28" />
        <updated date="2011-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2372.html">CVE-2011-2372</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2995.html">CVE-2011-2995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2998.html">CVE-2011-2998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2999.html">CVE-2011-2999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3000.html">CVE-2011-3000</cve>
                <bugzilla href="http://bugzilla.redhat.com/741902" id="741902">CVE-2011-2995 Mozilla: Miscellaneous memory safety hazards  (MFSA 2011-36)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741904" id="741904">CVE-2011-2999 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741905" id="741905">CVE-2011-3000 Mozilla:Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741917" id="741917">CVE-2011-2372 Mozilla:Code installation through holding down Enter (MFSA 2011-40)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741924" id="741924">CVE-2011-2998 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111342005" comment="thunderbird is earlier than 0:3.1.15-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111343" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1343: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1343.html" />
          <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html" />
          <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way Thunderbird handled large
JavaScript regular expressions. An HTML mail message containing malicious
JavaScript could cause Thunderbird to access already freed memory, causing
Thunderbird to crash or, potentially, execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2011-2998)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-28" />
        <updated date="2011-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2998.html">CVE-2011-2998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2999.html">CVE-2011-2999</cve>
                <bugzilla href="http://bugzilla.redhat.com/741904" id="741904">CVE-2011-2999 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741924" id="741924">CVE-2011-2998 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111343002" comment="thunderbird is earlier than 0:1.5.0.12-44.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111343005" comment="thunderbird is earlier than 0:2.0.0.24-26.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111344" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1344: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1344.html" />
          <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html" />
          <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html" />
    
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey handled frame objects with certain
names. An attacker could use this flaw to cause a plug-in to grant its
content access to another site or the local file system, violating the
same-origin policy. (CVE-2011-2999)

An integer underflow flaw was found in the way SeaMonkey handled large
JavaScript regular expressions. A web page containing malicious JavaScript
could cause SeaMonkey to access already freed memory, causing SeaMonkey to
crash or, potentially, execute arbitrary code with the privileges of the
user running SeaMonkey. (CVE-2011-2998)
 
All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-09-28" />
        <updated date="2011-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2998.html">CVE-2011-2998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2999.html">CVE-2011-2999</cve>
                <bugzilla href="http://bugzilla.redhat.com/741904" id="741904">CVE-2011-2999 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/741924" id="741924">CVE-2011-2998 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344004" comment="seamonkey-mail is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344002" comment="seamonkey is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344012" comment="seamonkey-devel is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344006" comment="seamonkey-chat is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111344010" comment="seamonkey-js-debugger is earlier than 0:1.0.9-76.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111349" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1349: rpm security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1349.html" />
          <reference source="CVE" ref_id="CVE-2011-3378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3378.html" />
    
    <description>The RPM Package Manager (RPM) is a command line driven package management
system capable of installing, uninstalling, verifying, querying, and
updating software packages.

Multiple flaws were found in the way the RPM library parsed package
headers. An attacker could create a specially-crafted RPM package that,
when queried or installed, would cause rpm to crash or, potentially,
execute arbitrary code. (CVE-2011-3378)

Note: Although an RPM package can, by design, execute arbitrary code when
installed, this issue would allow a specially-crafted RPM package to
execute arbitrary code before its digital signature has been verified.
Package downloads from the Red Hat Network remain secure due to certificate
checks performed on the secure connection.

All RPM users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running applications linked
against the RPM library must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-03" />
        <updated date="2011-10-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3378.html">CVE-2011-3378</cve>
                <bugzilla href="http://bugzilla.redhat.com/741606" id="741606">CVE-2011-3378 rpm: crashes and overflows on malformed header</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_aus</cpe>
            <cpe>cpe:/o:redhat:rhel_els</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349004" comment="rpm-devel is earlier than 0:4.3.3-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349005" comment="rpm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349012" comment="rpm-python is earlier than 0:4.3.3-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349013" comment="rpm-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349002" comment="rpm is earlier than 0:4.3.3-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349003" comment="rpm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349008" comment="rpm-libs is earlier than 0:4.3.3-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349009" comment="rpm-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349006" comment="popt is earlier than 0:1.9.1-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349007" comment="popt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349010" comment="rpm-build is earlier than 0:4.3.3-35_nonptl.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349011" comment="rpm-build is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349021" comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349022" comment="rpm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349017" comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349018" comment="rpm-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349015" comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349016" comment="rpm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349027" comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349028" comment="rpm-apidocs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349025" comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349026" comment="rpm-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349019" comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349020" comment="popt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349023" comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349024" comment="rpm-build is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349037" comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349038" comment="rpm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349035" comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349036" comment="rpm-python is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349033" comment="rpm is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349034" comment="rpm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349045" comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349046" comment="rpm-apidocs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349043" comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349044" comment="rpm-cron is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349041" comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349042" comment="rpm-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111349039" comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111349040" comment="rpm-build is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111350" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1350: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1350.html" />
          <reference source="CVE" ref_id="CVE-2011-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1160.html" />
          <reference source="CVE" ref_id="CVE-2011-1745" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1745.html" />
          <reference source="CVE" ref_id="CVE-2011-1746" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1746.html" />
          <reference source="CVE" ref_id="CVE-2011-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1833.html" />
          <reference source="CVE" ref_id="CVE-2011-2022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2022.html" />
          <reference source="CVE" ref_id="CVE-2011-2484" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2484.html" />
          <reference source="CVE" ref_id="CVE-2011-2496" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2496.html" />
          <reference source="CVE" ref_id="CVE-2011-2521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2521.html" />
          <reference source="CVE" ref_id="CVE-2011-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2723.html" />
          <reference source="CVE" ref_id="CVE-2011-2898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2898.html" />
          <reference source="CVE" ref_id="CVE-2011-2918" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2918.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Flaws in the AGPGART driver implementation when handling certain IOCTL
commands could allow a local user to cause a denial of service or escalate
their privileges. (CVE-2011-1745, CVE-2011-2022, Important)

* An integer overflow flaw in agp_allocate_memory() could allow a local
user to cause a denial of service or escalate their privileges.
(CVE-2011-1746, Important)

* A race condition flaw was found in the Linux kernel's eCryptfs
implementation. A local attacker could use the mount.ecryptfs_private
utility to mount (and then access) a directory they would otherwise not
have access to. Note: To correct this issue, the RHSA-2011:1241
ecryptfs-utils update, which provides the user-space part of the fix, must
also be installed. (CVE-2011-1833, Moderate)

* A denial of service flaw was found in the way the taskstats subsystem
handled the registration of process exit handlers. A local, unprivileged
user could register an unlimited amount of these handlers, leading to
excessive CPU time and memory use. (CVE-2011-2484, Moderate)

* A flaw was found in the way mapping expansions were handled. A local,
unprivileged user could use this flaw to cause a wrapping condition,
triggering a denial of service. (CVE-2011-2496, Moderate)

* A flaw was found in the Linux kernel's Performance Events implementation.
It could falsely lead the NMI (Non-Maskable Interrupt) Watchdog to detect a
lockup and panic the system. A local, unprivileged user could use this flaw
to cause a denial of service (kernel panic) using the perf tool.
(CVE-2011-2521, Moderate)

* A flaw in skb_gro_header_slow() in the Linux kernel could lead to GRO
(Generic Receive Offload) fields being left in an inconsistent state. An
attacker on the local network could use this flaw to trigger a denial of
service. GRO is enabled by default in all network drivers that support it.
(CVE-2011-2723, Moderate)

* A flaw was found in the way the Linux kernel's Performance Events
implementation handled PERF_COUNT_SW_CPU_CLOCK counter overflow. A local,
unprivileged user could use this flaw to cause a denial of service.
(CVE-2011-2918, Moderate)

* A flaw was found in the Linux kernel's Trusted Platform Module (TPM)
implementation. A local, unprivileged user could use this flaw to leak
information to user-space. (CVE-2011-1160, Low)

* Flaws were found in the tpacket_rcv() and packet_recvmsg() functions in
the Linux kernel. A local, unprivileged user could use these flaws to leak
information to user-space. (CVE-2011-2898, Low)

Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting
CVE-2011-1745, CVE-2011-2022, CVE-2011-1746, and CVE-2011-2484; the Ubuntu
Security Team for reporting CVE-2011-1833; Robert Swiecki for reporting
CVE-2011-2496; Li Yu for reporting CVE-2011-2521; Brent Meshier for
reporting CVE-2011-2723; and Peter Huewe for reporting CVE-2011-1160. The
Ubuntu Security Team acknowledges Vasiliy Kulikov of Openwall and Dan
Rosenberg as the original reporters of CVE-2011-1833.

This update also fixes various bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-05" />
        <updated date="2011-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1160.html">CVE-2011-1160</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1745.html">CVE-2011-1745</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1746.html">CVE-2011-1746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1833.html">CVE-2011-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2022.html">CVE-2011-2022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2484.html">CVE-2011-2484</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2496.html">CVE-2011-2496</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2521.html">CVE-2011-2521</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2723.html">CVE-2011-2723</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2898.html">CVE-2011-2898</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2918.html">CVE-2011-2918</cve>
                <bugzilla href="http://bugzilla.redhat.com/684671" id="684671">CVE-2011-1160 kernel: tpm infoleaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698996" id="698996">CVE-2011-1745 CVE-2011-2022 kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/698998" id="698998">CVE-2011-1746 kernel: agp: insufficient page_count parameter checking in agp_allocate_memory()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/713463" id="713463">UV: fscache taints kernel; NFS requires fscache; NFS taints kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/715436" id="715436">CVE-2011-2484 kernel: taskstats: duplicate entries in listener mode can lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716538" id="716538">CVE-2011-2496 kernel: mm: avoid wrapping vm_pgoff in mremap() and stack expansions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/719228" id="719228">CVE-2011-2521 kernel: perf, x86: fix Intel fixed counters base initialization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/726552" id="726552">CVE-2011-2723 kernel: gro: only reset frag0 when skb can be pulled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728023" id="728023">CVE-2011-2898 kernel: af_packet: infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730706" id="730706">CVE-2011-2918 kernel: perf: Fix software event overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/731172" id="731172">CVE-2011-1833 kernel: ecryptfs: mount source TOCTOU race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/732379" id="732379">[bnx2x_extract_max_cfg:1079(ethxx)]Illegal configuration detected for Max BW - using 100 instead [rhel-6.1.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350023" comment="kernel-firmware is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350007" comment="kernel-headers is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350005" comment="kernel is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350025" comment="kernel-doc is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350011" comment="kernel-devel is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350013" comment="perf is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350015" comment="kernel-debug is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350019" comment="kernel-kdump is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350017" comment="kernel-debug-devel is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350021" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111350009" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.17.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111356" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1356: openswan security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1356-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1356.html" />
          <reference source="CVE" ref_id="CVE-2011-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3380.html" />
    
    <description>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks.

A NULL pointer dereference flaw was found in the way Openswan's pluto IKE
daemon handled certain error conditions. A remote, unauthenticated attacker
could send a specially-crafted IKE packet that would crash the pluto
daemon. (CVE-2011-3380)

Red Hat would like to thank the Openswan project for reporting this issue.
Upstream acknowledges Paul Wouters as the original reporter.

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the ipsec service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-05" />
        <updated date="2011-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3380.html">CVE-2011-3380</cve>
                <bugzilla href="http://bugzilla.redhat.com/742065" id="742065">CVE-2011-3380 openswan: IKE invalid key length allows remote unauthenticated user to crash openswan</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111356005" comment="openswan is earlier than 0:2.6.32-4.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111356006" comment="openswan is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111356007" comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111356008" comment="openswan-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111359" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1359: xorg-x11-server security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1359.html" />
          <reference source="CVE" ref_id="CVE-2010-4818" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4818.html" />
          <reference source="CVE" ref_id="CVE-2010-4819" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4819.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple input sanitization flaws were found in the X.Org GLX (OpenGL
extension to the X Window System) extension. A malicious, authorized client
could use these flaws to crash the X.Org server or, potentially, execute
arbitrary code with root privileges. (CVE-2010-4818)

An input sanitization flaw was found in the X.Org Render extension. A
malicious, authorized client could use this flaw to leak arbitrary memory
from the X.Org server process, or possibly crash the X.Org server.
(CVE-2010-4819)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues. All running X.Org
server instances must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-06" />
        <updated date="2011-10-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4818.html">CVE-2010-4818</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4819.html">CVE-2010-4819</cve>
                <bugzilla href="http://bugzilla.redhat.com/740954" id="740954">CVE-2010-4818 X.org: multiple GLX input sanitization flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740961" id="740961">CVE-2010-4819 X.org: ProcRenderAddGlyphs input sanitization flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359016" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359017" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359014" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359015" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359004" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359005" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359006" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359007" comment="xorg-x11-server-Xvnc-source is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359012" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359013" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359008" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359009" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359002" comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359003" comment="xorg-x11-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359010" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359011" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359038" comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359039" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359036" comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359037" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359032" comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359033" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359024" comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359025" comment="xorg-x11-server-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359028" comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359029" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359022" comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359023" comment="xorg-x11-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359034" comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359035" comment="xorg-x11-server-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359026" comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359027" comment="xorg-x11-server-source is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111359030" comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111359031" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111360" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1360: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1360-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1360.html" />
          <reference source="CVE" ref_id="CVE-2010-4818" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4818.html" />
          <reference source="CVE" ref_id="CVE-2010-4819" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4819.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple input sanitization flaws were found in the X.Org GLX (OpenGL
extension to the X Window System) extension. A malicious, authorized client
could use these flaws to crash the X.Org server or, potentially, execute
arbitrary code with root privileges. (CVE-2010-4818)

An input sanitization flaw was found in the X.Org Render extension. A
malicious, authorized client could use this flaw to leak arbitrary memory
from the X.Org server process, or possibly crash the X.Org server.
(CVE-2010-4819)

Users of xorg-x11 should upgrade to these updated packages, which contain a
backported patch to resolve these issues. All running X.Org server
instances must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-06" />
        <updated date="2011-10-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4818.html">CVE-2010-4818</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2010-4819.html">CVE-2010-4819</cve>
                <bugzilla href="http://bugzilla.redhat.com/740954" id="740954">CVE-2010-4818 X.org: multiple GLX input sanitization flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740961" id="740961">CVE-2010-4819 X.org: ProcRenderAddGlyphs input sanitization flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360004" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360022" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432037" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360034" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432033" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360028" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432023" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360024" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432027" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360014" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432017" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360010" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432021" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360008" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360032" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432011" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360020" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432025" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360030" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432035" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360026" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432005" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360016" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432007" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360006" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432019" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360036" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432031" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360018" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432009" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111360012" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110432029" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111371" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1371: pidgin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1371-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1371.html" />
          <reference source="CVE" ref_id="CVE-2011-1091" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1091.html" />
          <reference source="CVE" ref_id="CVE-2011-3594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3594.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted SILC message. (CVE-2011-3594)

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

Red Hat would like to thank the Pidgin project for reporting CVE-2011-1091.
Upstream acknowledges Marius Wachtler as the original reporter of
CVE-2011-1091.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-13" />
        <updated date="2011-10-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1091.html">CVE-2011-1091</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3594.html">CVE-2011-3594</cve>
                <bugzilla href="http://bugzilla.redhat.com/683031" id="683031">CVE-2011-1091 Pidgin: Multiple NULL pointer dereference flaws in Yahoo protocol plug-in</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/743481" id="743481">CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371014" comment="libpurple-perl is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371015" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371010" comment="libpurple is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371011" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371004" comment="finch is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371005" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371002" comment="pidgin is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371018" comment="pidgin-devel is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371019" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371016" comment="finch-devel is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371017" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371012" comment="pidgin-perl is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371013" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371008" comment="libpurple-devel is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371009" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371006" comment="libpurple-tcl is earlier than 0:2.6.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371007" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371035" comment="libpurple-perl is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371036" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371027" comment="libpurple is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371028" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371023" comment="finch is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371024" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371021" comment="pidgin is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371022" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371037" comment="finch-devel is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371038" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371033" comment="libpurple-devel is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371034" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371031" comment="pidgin-devel is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371032" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371025" comment="pidgin-perl is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371026" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111371029" comment="libpurple-tcl is earlier than 0:2.6.6-5.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111371030" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111377" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1377: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1377.html" />
          <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

A signedness issue was found in the way the crypt() function in the
PostgreSQL pgcrypto module handled 8-bit characters in passwords when using
Blowfish hashing. Up to three characters immediately preceding a non-ASCII
character (one with the high bit set) had no effect on the hash result,
thus shortening the effective password length. This made brute-force
guessing more efficient as several different passwords were hashed to the
same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to applications that store user passwords, hashed
with Blowfish using the PostgreSQL crypt() function, in a back-end
PostgreSQL database. Unsafe processing can be re-enabled for specific
passwords (allowing affected users to log in) by changing their hash prefix
to "$2x$".

For Red Hat Enterprise Linux 6, the updated postgresql packages upgrade
PostgreSQL to version 8.4.9. Refer to the PostgreSQL Release Notes for a
full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

For Red Hat Enterprise Linux 4 and 5, the updated postgresql packages
contain a backported patch.

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-17" />
        <updated date="2011-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2483.html">CVE-2011-2483</cve>
                <bugzilla href="http://bugzilla.redhat.com/715025" id="715025">CVE-2011-2483 crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377020" comment="postgresql-jdbc is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197064" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377016" comment="postgresql-docs is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197060" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377010" comment="postgresql-devel is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197058" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377022" comment="postgresql-test is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197054" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377018" comment="postgresql-contrib is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197052" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377006" comment="postgresql-libs is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197062" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377012" comment="postgresql-tcl is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197056" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377002" comment="postgresql is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197048" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377014" comment="postgresql-server is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197066" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377008" comment="postgresql-python is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197068" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377004" comment="postgresql-pl is earlier than 0:7.4.30-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197050" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377035" comment="postgresql-docs is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197005" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377029" comment="postgresql-devel is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197017" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377033" comment="postgresql-test is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197009" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377031" comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197007" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377027" comment="postgresql-libs is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197015" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377037" comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197019" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377025" comment="postgresql is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377043" comment="postgresql-python is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197011" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377041" comment="postgresql-server is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197013" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377039" comment="postgresql-pl is earlier than 0:8.1.23-1.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197021" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377067" comment="postgresql-pltcl is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197039" comment="postgresql-pltcl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377061" comment="postgresql-docs is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197037" comment="postgresql-docs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377055" comment="postgresql-devel is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197035" comment="postgresql-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377063" comment="postgresql-contrib is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197045" comment="postgresql-contrib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377053" comment="postgresql-plperl is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197033" comment="postgresql-plperl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377051" comment="postgresql-test is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197031" comment="postgresql-test is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377059" comment="postgresql-plpython is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197029" comment="postgresql-plpython is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377065" comment="postgresql-libs is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197041" comment="postgresql-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377049" comment="postgresql is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197027" comment="postgresql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111377057" comment="postgresql-server is earlier than 0:8.4.9-1.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110197043" comment="postgresql-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111378" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1378: postgresql84 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1378-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1378.html" />
          <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

A signedness issue was found in the way the crypt() function in the
PostgreSQL pgcrypto module handled 8-bit characters in passwords when using
Blowfish hashing. Up to three characters immediately preceding a non-ASCII
character (one with the high bit set) had no effect on the hash result,
thus shortening the effective password length. This made brute-force
guessing more efficient as several different passwords were hashed to the
same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to applications that store user passwords, hashed
with Blowfish using the PostgreSQL crypt() function, in a back-end
PostgreSQL database. Unsafe processing can be re-enabled for specific
passwords (allowing affected users to log in) by changing their hash prefix
to "$2x$".

These updated postgresql84 packages upgrade PostgreSQL to version 8.4.9.
Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release.html

All PostgreSQL users are advised to upgrade to these updated packages,
which correct this issue. If the postgresql service is running, it will be
automatically restarted after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-17" />
        <updated date="2011-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2483.html">CVE-2011-2483</cve>
                <bugzilla href="http://bugzilla.redhat.com/715025" id="715025">CVE-2011-2483 crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378008" comment="postgresql84-tcl is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198025" comment="postgresql84-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378024" comment="postgresql84-docs is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198005" comment="postgresql84-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378020" comment="postgresql84-python is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198015" comment="postgresql84-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378016" comment="postgresql84-plpython is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198011" comment="postgresql84-plpython is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378018" comment="postgresql84-test is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198009" comment="postgresql84-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378014" comment="postgresql84-server is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198007" comment="postgresql84-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378004" comment="postgresql84-libs is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198019" comment="postgresql84-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378022" comment="postgresql84-plperl is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198017" comment="postgresql84-plperl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378006" comment="postgresql84-pltcl is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198013" comment="postgresql84-pltcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378010" comment="postgresql84-devel is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198023" comment="postgresql84-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378002" comment="postgresql84 is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198003" comment="postgresql84 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111378012" comment="postgresql84-contrib is earlier than 0:8.4.9-1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110198021" comment="postgresql84-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111379" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1379: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1379-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1379.html" />
          <reference source="CVE" ref_id="CVE-2011-1527" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1527.html" />
          <reference source="CVE" ref_id="CVE-2011-1528" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1528.html" />
          <reference source="CVE" ref_id="CVE-2011-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1529.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third-party, the Key Distribution Center (KDC).

Multiple NULL pointer dereference and assertion failure flaws were found
in the MIT Kerberos KDC when it was configured to use an LDAP (Lightweight
Directory Access Protocol) or Berkeley Database (Berkeley DB) back end. A
remote attacker could use these flaws to crash the KDC. (CVE-2011-1527,
CVE-2011-1528, CVE-2011-1529)

Red Hat would like to thank the MIT Kerberos project for reporting the
CVE-2011-1527 issue. Upstream acknowledges Andrej Ota as the original
reporter of CVE-2011-1527.

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct these issues. After installing the updated
packages, the krb5kdc daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-18" />
        <updated date="2011-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1527.html">CVE-2011-1527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1528.html">CVE-2011-1528</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1529.html">CVE-2011-1529</cve>
                <bugzilla href="http://bugzilla.redhat.com/737711" id="737711">CVE-2011-1527 CVE-2011-1528 CVE-2011-1529 krb5: KDC denial of service vulnerabilities (MITKRB5-SA-2011-006)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379017" comment="krb5-libs is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200008" comment="krb5-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379007" comment="krb5-pkinit-openssl is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200016" comment="krb5-pkinit-openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379015" comment="krb5-devel is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200014" comment="krb5-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379011" comment="krb5-server is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200018" comment="krb5-server is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379013" comment="krb5-server-ldap is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200012" comment="krb5-server-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379005" comment="krb5 is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200006" comment="krb5 is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111379009" comment="krb5-workstation is earlier than 0:1.9-9.el6_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110200010" comment="krb5-workstation is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111380" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1380: java-1.6.0-openjdk security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1380-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1380.html" />
          <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html" />
          <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html" />
          <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html" />
          <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html" />
          <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html" />
          <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html" />
          <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html" />
          <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html" />
          <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html" />
          <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html" />
          <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html" />
          <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html" />
          <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

A flaw was found in the Java RMI (Remote Method Invocation) registry
implementation. A remote RMI client could use this flaw to execute
arbitrary code on the RMI server running the registry. (CVE-2011-3556)

A flaw was found in the Java RMI registry implementation. A remote RMI
client could use this flaw to execute code on the RMI server with
unrestricted privileges. (CVE-2011-3557)

A flaw was found in the IIOP (Internet Inter-Orb Protocol) deserialization
code. An untrusted Java application or applet running in a sandbox could
use this flaw to bypass sandbox restrictions by deserializing
specially-crafted input. (CVE-2011-3521)

It was found that the Java ScriptingEngine did not properly restrict the
privileges of sandboxed applications. An untrusted Java application or
applet running in a sandbox could use this flaw to bypass sandbox
restrictions. (CVE-2011-3544)

A flaw was found in the AWTKeyStroke implementation. An untrusted Java
application or applet running in a sandbox could use this flaw to bypass
sandbox restrictions. (CVE-2011-3548)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the Java2D code used to perform transformations of graphic shapes
and images. An untrusted Java application or applet running in a sandbox
could use this flaw to bypass sandbox restrictions. (CVE-2011-3551)

An insufficient error checking flaw was found in the unpacker for JAR files
in pack200 format. A specially-crafted JAR file could use this flaw to
crash the Java Virtual Machine (JVM) or, possibly, execute arbitrary code
with JVM privileges. (CVE-2011-3554)

It was found that HttpsURLConnection did not perform SecurityManager checks
in the setSSLSocketFactory method. An untrusted Java application or applet
running in a sandbox could use this flaw to bypass connection restrictions
defined in the policy. (CVE-2011-3560)

A flaw was found in the way the SSL 3 and TLS 1.0 protocols used block
ciphers in cipher-block chaining (CBC) mode. An attacker able to perform a
chosen plain text attack against a connection mixing trusted and untrusted
data could use this flaw to recover portions of the trusted data sent over
the connection. (CVE-2011-3389)

Note: This update mitigates the CVE-2011-3389 issue by splitting the first
application data record byte to a separate SSL/TLS protocol record. This
mitigation may cause compatibility issues with some SSL/TLS implementations
and can be disabled using the jsse.enableCBCProtection boolean property.
This can be done on the command line by appending the flag
"-Djsse.enableCBCProtection=false" to the java command.

An information leak flaw was found in the InputStream.skip implementation.
An untrusted Java application or applet could possibly use this flaw to
obtain bytes skipped by other threads. (CVE-2011-3547)

A flaw was found in the Java HotSpot virtual machine. An untrusted Java
application or applet could use this flaw to disclose portions of the VM
memory, or cause it to crash. (CVE-2011-3558)

The Java API for XML Web Services (JAX-WS) implementation in OpenJDK was
configured to include the stack trace in error messages sent to clients. A
remote client could possibly use this flaw to obtain sensitive information.
(CVE-2011-3553)

It was found that Java applications running with SecurityManager
restrictions were allowed to use too many UDP sockets by default. If
multiple instances of a malicious application were started at the same
time, they could exhaust all available UDP sockets on the system.
(CVE-2011-3552)

This erratum also upgrades the OpenJDK package to IcedTea6 1.9.10. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-18" />
        <updated date="2011-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3389.html">CVE-2011-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3521.html">CVE-2011-3521</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3544.html">CVE-2011-3544</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3547.html">CVE-2011-3547</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3548.html">CVE-2011-3548</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3551.html">CVE-2011-3551</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3552.html">CVE-2011-3552</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3553.html">CVE-2011-3553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3554.html">CVE-2011-3554</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3556.html">CVE-2011-3556</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3557.html">CVE-2011-3557</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3558.html">CVE-2011-3558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3560.html">CVE-2011-3560</cve>
                <bugzilla href="http://bugzilla.redhat.com/737506" id="737506">CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745379" id="745379">CVE-2011-3560 OpenJDK: missing checkSetFactory calls in HttpsURLConnection (JSSE, 7096936)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745387" id="745387">CVE-2011-3547 OpenJDK: InputStream skip() information leak (Networking/IO, 7000600)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745391" id="745391">CVE-2011-3551 OpenJDK: Java2D TransformHelper integer overflow (2D, 7023640)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745397" id="745397">CVE-2011-3552 OpenJDK: excessive default UDP socket limit under SecurityManager (Networking, 7032417)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745399" id="745399">CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745442" id="745442">CVE-2011-3521 OpenJDK: IIOP deserialization code execution (Deserialization, 7055902)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745447" id="745447">CVE-2011-3554 OpenJDK: insufficient pack200 JAR files uncompress error checks (Runtime, 7057857)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745459" id="745459">CVE-2011-3556 OpenJDK: RMI DGC server remote code execution (RMI, 7077466)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745464" id="745464">CVE-2011-3557 OpenJDK: RMI registry privileged code execution (RMI, 7083012)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745473" id="745473">CVE-2011-3548 OpenJDK: mutable static AWTKeyStroke.ctor (AWT, 7019773)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745476" id="745476">CVE-2011-3553 OpenJDK: JAX-WS stack-traces information leak (JAX-WS, 7046794)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/745492" id="745492">CVE-2011-3558 OpenJDK: Hotspot unspecified issue (Hotspot, 7070134)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380006" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176005" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380010" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380008" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176007" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380004" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110176009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380016" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214017" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380020" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214019" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380024" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214023" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380018" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214021" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111380022" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110214025" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111384" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1384: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
      <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
      <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1384.html" />
      <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html" />
      <reference source="CVE" ref_id="CVE-2011-3516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3516.html" />
      <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html" />
      <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html" />
      <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html" />
      <reference source="CVE" ref_id="CVE-2011-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3546.html" />
      <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html" />
      <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html" />
      <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html" />
      <reference source="CVE" ref_id="CVE-2011-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3550.html" />
      <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html" />
      <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html" />
      <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html" />
      <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html" />
      <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html" />
      <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html" />
      <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html" />
      <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html" />
      <reference source="CVE" ref_id="CVE-2011-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3561.html" />
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch page, listed in the References section. (CVE-2011-3389,
CVE-2011-3516, CVE-2011-3521, CVE-2011-3544, CVE-2011-3545, CVE-2011-3546,
CVE-2011-3547, CVE-2011-3548, CVE-2011-3549, CVE-2011-3550, CVE-2011-3551,
CVE-2011-3552, CVE-2011-3553, CVE-2011-3554, CVE-2011-3555, CVE-2011-3556,
CVE-2011-3557, CVE-2011-3558, CVE-2011-3560, CVE-2011-3561)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide JDK and JRE 6 Update 29 and resolve these issues.
All running instances of Sun Java must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-19" />
        <updated date="2011-10-19" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3389.html">CVE-2011-3389</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3516.html">CVE-2011-3516</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3521.html">CVE-2011-3521</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3544.html">CVE-2011-3544</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3545.html">CVE-2011-3545</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3546.html">CVE-2011-3546</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3547.html">CVE-2011-3547</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3548.html">CVE-2011-3548</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3549.html">CVE-2011-3549</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3550.html">CVE-2011-3550</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3551.html">CVE-2011-3551</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3552.html">CVE-2011-3552</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3553.html">CVE-2011-3553</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3554.html">CVE-2011-3554</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3556.html">CVE-2011-3556</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3557.html">CVE-2011-3557</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3558.html">CVE-2011-3558</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3560.html">CVE-2011-3560</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3561.html">CVE-2011-3561</cve>
        <bugzilla href="http://bugzilla.redhat.com/737506" id="737506">CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745379" id="745379">CVE-2011-3560 OpenJDK: missing checkSetFactory calls in HttpsURLConnection (JSSE, 7096936)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745387" id="745387">CVE-2011-3547 OpenJDK: InputStream skip() information leak (Networking/IO, 7000600)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745391" id="745391">CVE-2011-3551 OpenJDK: Java2D TransformHelper integer overflow (2D, 7023640)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745397" id="745397">CVE-2011-3552 OpenJDK: excessive default UDP socket limit under SecurityManager (Networking, 7032417)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745399" id="745399">CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745442" id="745442">CVE-2011-3521 OpenJDK: IIOP deserialization code execution (Deserialization, 7055902)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745447" id="745447">CVE-2011-3554 OpenJDK: insufficient pack200 JAR files uncompress error checks (Runtime, 7057857)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745459" id="745459">CVE-2011-3556 OpenJDK: RMI DGC server remote code execution (RMI, 7077466)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745464" id="745464">CVE-2011-3557 OpenJDK: RMI registry privileged code execution (RMI, 7083012)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745473" id="745473">CVE-2011-3548 OpenJDK: mutable static AWTKeyStroke.ctor (AWT, 7019773)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745476" id="745476">CVE-2011-3553 OpenJDK: JAX-WS stack-traces information leak (JAX-WS, 7046794)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745492" id="745492">CVE-2011-3558 OpenJDK: Hotspot unspecified issue (Hotspot, 7070134)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747191" id="747191">CVE-2011-3545 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Sound)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747198" id="747198">CVE-2011-3549 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Swing)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747200" id="747200">CVE-2011-3550 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (AWT)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747203" id="747203">CVE-2011-3516 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747205" id="747205">CVE-2011-3546 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747206" id="747206">CVE-2011-3555 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (JRE)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747208" id="747208">CVE-2011-3561 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_extras</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384010" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282009" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384002" comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384008" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282013" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384006" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282007" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384012" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282005" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384004" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282011" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384026" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282025" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384018" comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282019" comment="java-1.6.0-sun is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384024" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282029" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384022" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282023" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384028" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282021" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111384020" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110282027" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111385" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1385-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1385.html" />
          <reference source="CVE" ref_id="CVE-2011-3365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3365.html" />
    
    <description>The kdelibs and kdelibs3 packages provide libraries for the K Desktop
Environment (KDE).

An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An
attacker could supply a specially-crafted SSL certificate (for example, via
a web page) to an application using KSSL, such as the Konqueror web
browser, causing misleading information to be presented to the user,
possibly tricking them into accepting the certificate as valid.
(CVE-2011-3365)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The desktop must be restarted (log out, then
log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-19" />
        <updated date="2011-10-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3365.html">CVE-2011-3365</cve>
                <bugzilla href="http://bugzilla.redhat.com/743054" id="743054">CVE-2011-3365 kdelibs: input validation failure in KSSL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385002" comment="kdelibs is earlier than 6:3.3.1-18.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385004" comment="kdelibs-devel is earlier than 6:3.3.1-18.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385011" comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385012" comment="kdelibs-apidocs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385007" comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385008" comment="kdelibs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385009" comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385010" comment="kdelibs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385021" comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385022" comment="kdelibs3-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385019" comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385020" comment="kdelibs3-apidocs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111385017" comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111385018" comment="kdelibs3 is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111386" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1386-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1386.html" />
          <reference source="CVE" ref_id="CVE-2009-4067" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4067.html" />
          <reference source="CVE" ref_id="CVE-2011-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1160.html" />
          <reference source="CVE" ref_id="CVE-2011-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1585.html" />
          <reference source="CVE" ref_id="CVE-2011-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1833.html" />
          <reference source="CVE" ref_id="CVE-2011-2484" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2484.html" />
          <reference source="CVE" ref_id="CVE-2011-2496" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2496.html" />
          <reference source="CVE" ref_id="CVE-2011-2695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2695.html" />
          <reference source="CVE" ref_id="CVE-2011-2699" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2699.html" />
          <reference source="CVE" ref_id="CVE-2011-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2723.html" />
          <reference source="CVE" ref_id="CVE-2011-2942" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2942.html" />
          <reference source="CVE" ref_id="CVE-2011-3131" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3131.html" />
          <reference source="CVE" ref_id="CVE-2011-3188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3188.html" />
          <reference source="CVE" ref_id="CVE-2011-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3191.html" />
          <reference source="CVE" ref_id="CVE-2011-3209" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3209.html" />
          <reference source="CVE" ref_id="CVE-2011-3347" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3347.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* The maximum file offset handling for ext4 file systems could allow a
local, unprivileged user to cause a denial of service. (CVE-2011-2695,
Important)

* IPv6 fragment identification value generation could allow a remote
attacker to disrupt a target system's networking, preventing legitimate
users from accessing its services. (CVE-2011-2699, Important)

* A malicious CIFS (Common Internet File System) server could send a
specially-crafted response to a directory read request that would result in
a denial of service or privilege escalation on a system that has a CIFS
share mounted. (CVE-2011-3191, Important)

* A local attacker could use mount.ecryptfs_private to mount (and then
access) a directory they would otherwise not have access to. Note: To
correct this issue, the RHSA-2011:1241 ecryptfs-utils update must also be
installed. (CVE-2011-1833, Moderate)

* A flaw in the taskstats subsystem could allow a local, unprivileged user
to cause excessive CPU time and memory use. (CVE-2011-2484, Moderate)

* Mapping expansion handling could allow a local, unprivileged user to
cause a denial of service. (CVE-2011-2496, Moderate)

* GRO (Generic Receive Offload) fields could be left in an inconsistent
state. An attacker on the local network could use this flaw to cause a
denial of service. GRO is enabled by default in all network drivers that
support it. (CVE-2011-2723, Moderate)

* RHSA-2011:1065 introduced a regression in the Ethernet bridge
implementation. If a system had an interface in a bridge, and an attacker
on the local network could send packets to that interface, they could cause
a denial of service on that system. Xen hypervisor and KVM (Kernel-based
Virtual Machine) hosts often deploy bridge interfaces. (CVE-2011-2942,
Moderate)

* A flaw in the Xen hypervisor IOMMU error handling implementation could
allow a privileged guest user, within a guest operating system that has
direct control of a PCI device, to cause performance degradation on the
host and possibly cause it to hang. (CVE-2011-3131, Moderate)

* IPv4 and IPv6 protocol sequence number and fragment ID generation could
allow a man-in-the-middle attacker to inject packets and possibly hijack
connections. Protocol sequence number and fragment IDs are now more random.
(CVE-2011-3188, Moderate)

* A flaw in the kernel's clock implementation could allow a local,
unprivileged user to cause a denial of service. (CVE-2011-3209, Moderate)

* Non-member VLAN (virtual LAN) packet handling for interfaces in
promiscuous mode and also using the be2net driver could allow an attacker
on the local network to cause a denial of service. (CVE-2011-3347,
Moderate)

* A flaw in the auerswald USB driver could allow a local, unprivileged user
to cause a denial of service or escalate their privileges by inserting a
specially-crafted USB device. (CVE-2009-4067, Low)

* A flaw in the Trusted Platform Module (TPM) implementation could allow a
local, unprivileged user to leak information to user space. (CVE-2011-1160,
Low)

* A local, unprivileged user could possibly mount a CIFS share that
requires authentication without knowing the correct password if the mount
was already mounted by another local user. (CVE-2011-1585, Low)

Red Hat would like to thank Fernando Gont for reporting CVE-2011-2699;
Darren Lavender for reporting CVE-2011-3191; the Ubuntu Security Team for
reporting CVE-2011-1833; Vasiliy Kulikov of Openwall for reporting
CVE-2011-2484; Robert Swiecki for reporting CVE-2011-2496; Brent Meshier
for reporting CVE-2011-2723; Dan Kaminsky for reporting CVE-2011-3188;
Yasuaki Ishimatsu for reporting CVE-2011-3209; Somnath Kotur for reporting
CVE-2011-3347; Rafael Dominguez Vega for reporting CVE-2009-4067; and Peter
Huewe for reporting CVE-2011-1160. The Ubuntu Security Team acknowledges
Vasiliy Kulikov of Openwall and Dan Rosenberg as the original reporters of
CVE-2011-1833.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-20" />
        <updated date="2011-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4067.html">CVE-2009-4067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1160.html">CVE-2011-1160</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1585.html">CVE-2011-1585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1833.html">CVE-2011-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2484.html">CVE-2011-2484</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2496.html">CVE-2011-2496</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2695.html">CVE-2011-2695</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2699.html">CVE-2011-2699</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2723.html">CVE-2011-2723</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2942.html">CVE-2011-2942</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3131.html">CVE-2011-3131</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3188.html">CVE-2011-3188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3191.html">CVE-2011-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3209.html">CVE-2011-3209</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3347.html">CVE-2011-3347</cve>
                <bugzilla href="http://bugzilla.redhat.com/684671" id="684671">CVE-2011-1160 kernel: tpm infoleaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/697394" id="697394">CVE-2011-1585 kernel: cifs session reuse</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/715436" id="715436">CVE-2011-2484 kernel: taskstats: duplicate entries in listener mode can lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/716538" id="716538">CVE-2011-2496 kernel: mm: avoid wrapping vm_pgoff in mremap() and stack expansions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722393" id="722393">CVE-2009-4067 kernel: usb: buffer overflow in auerswald_probe()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/722557" id="722557">CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/723429" id="723429">CVE-2011-2699 kernel: ipv6: make fragment identifications less predictable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/726552" id="726552">CVE-2011-2723 kernel: gro: only reset frag0 when skb can be pulled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/728518" id="728518">win2003 i386 guest BSOD when created with e1000 nic [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730341" id="730341">CVE-2011-3131 kernel: xen: IOMMU fault livelock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730682" id="730682">[EL5.7] igb: failed to activate WOL on 2nd LAN port on i350 [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730686" id="730686">Huge performance regression in NFS client [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/730917" id="730917">CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/731172" id="731172">CVE-2011-1833 kernel: ecryptfs: mount source TOCTOU race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/732658" id="732658">CVE-2011-3188 kernel: net: improve sequence number generation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/732869" id="732869">CVE-2011-3191 kernel: cifs: signedness issue in CIFSFindNext()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/732878" id="732878">CVE-2011-3209 kernel: panic occurs when clock_gettime() is called</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/733665" id="733665">Incorrect values in /proc/sys/vm/dirty_writeback_centises and dirty_expire_centisecs [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/736425" id="736425">CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/738389" id="738389">Patch needed to allow MTU >1500 on vif prior to connecting to bridge [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/738392" id="738392">netfront MTU drops to 1500 after domain migration [rhel-5.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/739823" id="739823">2.6.18-238.1.1.el5 or newer won't boot under Xen HVM due to linux-2.6-virt-nmi-don-t-print-nmi-stuck-messages-on-guests.patch [rhel-5.7.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386004" comment="kernel-headers is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386002" comment="kernel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386024" comment="kernel-doc is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386020" comment="kernel-PAE-devel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386006" comment="kernel-devel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386010" comment="kernel-debug is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386016" comment="kernel-kdump is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386012" comment="kernel-xen-devel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386008" comment="kernel-debug-devel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386022" comment="kernel-PAE is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386018" comment="kernel-kdump-devel is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111386014" comment="kernel-xen is earlier than 0:2.6.18-274.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111391" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1391: httpd security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1391.html" />
          <reference source="CVE" ref_id="CVE-2011-3348" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3348.html" />
          <reference source="CVE" ref_id="CVE-2011-3368" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3368.html" />
    
    <description>The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

It was discovered that mod_proxy_ajp incorrectly returned an "Internal
Server Error" response when processing certain malformed HTTP requests,
which caused the back-end server to be marked as failed in configurations
where mod_proxy was used in load balancer mode. A remote attacker could
cause mod_proxy to not send requests to back-end AJP (Apache JServ
Protocol) servers for the retry timeout period or until all back-end
servers were marked as failed. (CVE-2011-3348)

Red Hat would like to thank Context Information Security for reporting the
CVE-2011-3368 issue.

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by the RHSA-2011:1245 update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions. (BZ#736592)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-20" />
        <updated date="2011-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3348.html">CVE-2011-3348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3368.html">CVE-2011-3368</cve>
                <bugzilla href="http://bugzilla.redhat.com/736592" id="736592">httpd: RHSA-2011:1245 regressions [rhel-6]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/736690" id="736690">CVE-2011-3348 httpd: mod_proxy_ajp remote temporary DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740045" id="740045">CVE-2011-3368 httpd: reverse web proxy vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111391013" comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245034" comment="httpd-manual is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111391009" comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245032" comment="httpd-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111391007" comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245028" comment="httpd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111391011" comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245030" comment="mod_ssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111391005" comment="httpd is earlier than 0:2.2.15-9.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245026" comment="httpd is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111392" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1392: httpd security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1392.html" />
          <reference source="CVE" ref_id="CVE-2011-3368" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3368.html" />
    
    <description>The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

Red Hat would like to thank Context Information Security for reporting this
issue.

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by the RHSA-2011:1245 update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions. (BZ#736593, BZ#736594)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-20" />
        <updated date="2011-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3368.html">CVE-2011-3368</cve>
                <bugzilla href="http://bugzilla.redhat.com/736593" id="736593">httpd: RHSA-2011:1245 regressions [rhel-5]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/736594" id="736594">httpd: RHSA-2011:1245 regressions [rhel-4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/740045" id="740045">CVE-2011-3368 httpd: reverse web proxy vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392008" comment="httpd-manual is earlier than 0:2.0.52-49.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245007" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392006" comment="httpd-suexec is earlier than 0:2.0.52-49.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392004" comment="httpd-devel is earlier than 0:2.0.52-49.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392010" comment="mod_ssl is earlier than 0:2.0.52-49.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245009" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392002" comment="httpd is earlier than 0:2.0.52-49.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392015" comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245016" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392019" comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245018" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392017" comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245020" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111392013" comment="httpd is earlier than 0:2.2.3-53.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111245014" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111401" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1401: xen security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1401-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1401.html" />
          <reference source="CVE" ref_id="CVE-2011-3346" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3346.html" />
    
    <description>The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise
Linux.

A buffer overflow flaw was found in the Xen hypervisor SCSI subsystem
emulation. An unprivileged, local guest user could provide a large number
of bytes that are used to zero out a fixed-sized buffer via a SAI READ
CAPACITY SCSI command, overwriting memory and causing the guest to crash.
(CVE-2011-3346)

This update also fixes the following bugs:

* Prior to this update, the vif-bridge script used a maximum transmission
unit (MTU) of 1500 for a new Virtual Interface (VIF). As a result, the MTU
of the VIF could differ from that of the target bridge. This update fixes
the VIF hot-plug script so that the default MTU for new VIFs will match
that of the target Xen hypervisor bridge. In combination with a new enough
kernel (RHSA-2011:1386), this enables the use of jumbo frames in Xen
hypervisor guests. (BZ#738608)

* Prior to this update, the network-bridge script set the MTU of the bridge
to 1500. As a result, the MTU of the Xen hypervisor bridge could differ
from that of the physical interface. This update fixes the network script
so the MTU of the bridge can be set higher than 1500, thus also providing
support for jumbo frames. Now, the MTU of the Xen hypervisor bridge will
match that of the physical interface. (BZ#738610)

* Red Hat Enterprise Linux 5.6 introduced an optimized migration handling
that speeds up the migration of guests with large memory. However, the new
migration procedure can theoretically cause data corruption. While no cases
were observed in practice, with this update, the xend daemon properly waits
for correct device release before the guest is started on a destination
machine, thus fixing this bug. (BZ#743850)

Note: Before a guest is using a new enough kernel (RHSA-2011:1386), the MTU
of the VIF will drop back to 1500 (if it was set higher) after migration.

All xen users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the xend service must be restarted for this update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-24" />
        <updated date="2011-10-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3346.html">CVE-2011-3346</cve>
                <bugzilla href="http://bugzilla.redhat.com/736038" id="736038">CVE-2011-3346 qemu: local DoS with SCSI CD-ROM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/738608" id="738608">vif (netback) should take its default MTU from the bridge</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/738610" id="738610">The network-bridge script does not set the MTU of the bridge to match the MTU of the physical interface</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111401002" comment="xen is earlier than 0:3.0.3-132.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111401004" comment="xen-libs is earlier than 0:3.0.3-132.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496007" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111401006" comment="xen-devel is earlier than 0:3.0.3-132.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110496005" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111402" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1402: freetype security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1402.html" />
          <reference source="CVE" ref_id="CVE-2011-3256" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3256.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.

Multiple input validation flaws were found in the way FreeType processed
bitmap font files. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3256)

Note: These issues only affected the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-25" />
        <updated date="2011-10-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3256.html">CVE-2011-3256</cve>
                <bugzilla href="http://bugzilla.redhat.com/746226" id="746226">CVE-2011-3256 FreeType FT_Bitmap_New integer overflow to buffer overflow, FreeType TT_Vary_Get_Glyph_Deltas improper input validation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402006" comment="freetype-utils is earlier than 0:2.1.9-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161005" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402002" comment="freetype is earlier than 0:2.1.9-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402004" comment="freetype-demos is earlier than 0:2.1.9-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161007" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402008" comment="freetype-devel is earlier than 0:2.1.9-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161009" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402011" comment="freetype is earlier than 0:2.2.1-28.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402012" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402013" comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402014" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402015" comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402016" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402021" comment="freetype is earlier than 0:2.3.11-6.el6_1.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085006" comment="freetype is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402023" comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085008" comment="freetype-demos is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111402025" comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085010" comment="freetype-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111409" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1409: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1409.html" />
          <reference source="CVE" ref_id="CVE-2011-3207" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3207.html" />
    
    <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An uninitialized variable use flaw was found in OpenSSL. This flaw could
cause an application using the OpenSSL Certificate Revocation List (CRL)
checking functionality to incorrectly accept a CRL that has a nextUpdate
date in the past. (CVE-2011-3207)

All OpenSSL users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. For the update to take effect, all
services linked to the OpenSSL library must be restarted, or the system
rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-10-26" />
        <updated date="2011-10-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3207.html">CVE-2011-3207</cve>
                <bugzilla href="http://bugzilla.redhat.com/736087" id="736087">CVE-2011-3207 openssl: CRL verification vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111409005" comment="openssl is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677006" comment="openssl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111409007" comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677012" comment="openssl-static is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111409009" comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677010" comment="openssl-perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111409011" comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110677008" comment="openssl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111422" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1422: openswan security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 6</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1422-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1422.html" />
          <reference source="CVE" ref_id="CVE-2011-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4073.html" />
    
    <description>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks.

A use-after-free flaw was found in the way Openswan's pluto IKE daemon used
cryptographic helpers. A remote, authenticated attacker could send a
specially-crafted IKE packet that would crash the pluto daemon. This issue
only affected SMP (symmetric multiprocessing) systems that have the
cryptographic helpers enabled. The helpers are disabled by default on Red
Hat Enterprise Linux 5, but enabled by default on Red Hat Enterprise Linux
6. (CVE-2011-4073)

Red Hat would like to thank the Openswan project for reporting this issue.
Upstream acknowledges Petar Tsankov, Mohammad Torabi Dashti and David Basin
of the information security group at ETH Zurich as the original reporters.

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the ipsec service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-02" />
        <updated date="2011-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4073.html">CVE-2011-4073</cve>
                <bugzilla href="http://bugzilla.redhat.com/748961" id="748961">CVE-2011-4073 openswan: use-after-free vulnerability leads to DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111422002" comment="openswan is earlier than 0:2.6.21-5.el5_7.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111422003" comment="openswan is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111422004" comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111422005" comment="openswan-doc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111422010" comment="openswan is earlier than 0:2.6.32-4.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111356006" comment="openswan is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111422012" comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111356008" comment="openswan-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111423" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1423: php53 and php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 6</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1423.html" />
          <reference source="CVE" ref_id="CVE-2011-0708" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0708.html" />
          <reference source="CVE" ref_id="CVE-2011-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1148.html" />
          <reference source="CVE" ref_id="CVE-2011-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1466.html" />
          <reference source="CVE" ref_id="CVE-2011-1468" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1468.html" />
          <reference source="CVE" ref_id="CVE-2011-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1469.html" />
          <reference source="CVE" ref_id="CVE-2011-1471" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1471.html" />
          <reference source="CVE" ref_id="CVE-2011-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1938.html" />
          <reference source="CVE" ref_id="CVE-2011-2202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2202.html" />
          <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A signedness issue was found in the way the PHP crypt() function handled
8-bit characters in passwords when using Blowfish hashing. Up to three
characters immediately preceding a non-ASCII character (one with the high
bit set) had no effect on the hash result, thus shortening the effective
password length. This made brute-force guessing more efficient as several
different passwords were hashed to the same value. (CVE-2011-2483)

Note: Due to the CVE-2011-2483 fix, after installing this update some users
may not be able to log in to PHP applications that hash passwords with
Blowfish using the PHP crypt() function. Refer to the upstream
"CRYPT_BLOWFISH security fix details" document, linked to in the
References, for details.

An insufficient input validation flaw, leading to a buffer over-read, was
found in the PHP exif extension. A specially-crafted image file could cause
the PHP interpreter to crash when a PHP script tries to extract
Exchangeable image file format (Exif) metadata from the image file.
(CVE-2011-0708)

An integer overflow flaw was found in the PHP calendar extension. A remote
attacker able to make a PHP script call SdnToJulian() with a large value
could cause the PHP interpreter to crash. (CVE-2011-1466)

Multiple memory leak flaws were found in the PHP OpenSSL extension. A
remote attacker able to make a PHP script use openssl_encrypt() or
openssl_decrypt() repeatedly could cause the PHP interpreter to use an
excessive amount of memory. (CVE-2011-1468)

A use-after-free flaw was found in the PHP substr_replace() function. If a
PHP script used the same variable as multiple function arguments, a remote
attacker could possibly use this to crash the PHP interpreter or, possibly,
execute arbitrary code. (CVE-2011-1148)

A bug in the PHP Streams component caused the PHP interpreter to crash if
an FTP wrapper connection was made through an HTTP proxy. A remote attacker
could possibly trigger this issue if a PHP script accepted an untrusted URL
to connect to. (CVE-2011-1469)

An integer signedness issue was found in the PHP zip extension. An attacker
could use a specially-crafted ZIP archive to cause the PHP interpreter to
use an excessive amount of CPU time until the script execution time limit
is reached. (CVE-2011-1471)

A stack-based buffer overflow flaw was found in the way the PHP socket
extension handled long AF_UNIX socket addresses. An attacker able to make a
PHP script connect to a long AF_UNIX socket address could use this flaw to
crash the PHP interpreter. (CVE-2011-1938)

An off-by-one flaw was found in PHP. If an attacker uploaded a file with a
specially-crafted file name it could cause a PHP script to attempt to write
a file to the root (/) directory. By default, PHP runs as the "apache"
user, preventing it from writing to the root directory. (CVE-2011-2202)

All php53 and php users should upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-02" />
        <updated date="2011-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-0708.html">CVE-2011-0708</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1148.html">CVE-2011-1148</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1466.html">CVE-2011-1466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1468.html">CVE-2011-1468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1469.html">CVE-2011-1469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1471.html">CVE-2011-1471</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1938.html">CVE-2011-1938</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2202.html">CVE-2011-2202</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2483.html">CVE-2011-2483</cve>
                <bugzilla href="http://bugzilla.redhat.com/680972" id="680972">CVE-2011-0708 php: buffer over-read in Exif extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/688958" id="688958">CVE-2011-1148 php: use-after-free vulnerability in substr_replace()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/689386" id="689386">CVE-2011-1466 php: Crash by converting serial day numbers (SDN) into Julian calendar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690899" id="690899">CVE-2011-1468 php: Multiple memory leaks in the OpenSSL extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690905" id="690905">CVE-2011-1469 php: DoS when using HTTP proxy with the FTP wrapper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/690915" id="690915">CVE-2011-1471 php: DoS (excessive CPU consumption) by processing certain Zip archive files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/709067" id="709067">CVE-2011-1938 php: stack-based buffer overflow in socket_connect()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/713194" id="713194">CVE-2011-2202 php: file path injection vulnerability in RFC1867 file upload filename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/715025" id="715025">CVE-2011-2483 crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423034" comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196029" comment="php53-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423018" comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196007" comment="php53-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423042" comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196025" comment="php53-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423040" comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196027" comment="php53-process is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423036" comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196043" comment="php53-intl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423012" comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196005" comment="php53-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423030" comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196013" comment="php53-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423028" comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196035" comment="php53-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423004" comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196015" comment="php53-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423002" comment="php53 is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196003" comment="php53 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423026" comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196019" comment="php53-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423020" comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196017" comment="php53-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423022" comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196037" comment="php53-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423014" comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196023" comment="php53-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423006" comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196041" comment="php53-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423038" comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196011" comment="php53-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423032" comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196039" comment="php53-pspell is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423024" comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196031" comment="php53-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423016" comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196021" comment="php53-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423010" comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196033" comment="php53-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423008" comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110196009" comment="php53-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423090" comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195020" comment="php-odbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423082" comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195024" comment="php-soap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423080" comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195056" comment="php-gd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423054" comment="php-common is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195010" comment="php-common is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423064" comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195028" comment="php-pspell is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423052" comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195008" comment="php-mysql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423048" comment="php is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195006" comment="php is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423086" comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195052" comment="php-xmlrpc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423094" comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195026" comment="php-enchant is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423070" comment="php-process is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195016" comment="php-process is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423056" comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195044" comment="php-cli is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423058" comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195042" comment="php-mbstring is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423074" comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195022" comment="php-xml is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423050" comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195014" comment="php-pgsql is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423096" comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195032" comment="php-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423088" comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195030" comment="php-intl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423066" comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195054" comment="php-dba is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423078" comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195048" comment="php-bcmath is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423076" comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195040" comment="php-imap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423072" comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195036" comment="php-snmp is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423060" comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195034" comment="php-zts is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423098" comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195012" comment="php-tidy is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423092" comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195038" comment="php-embedded is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423084" comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195050" comment="php-recode is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423068" comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195046" comment="php-ldap is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111423062" comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110195018" comment="php-pdo is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111424" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1424: perl security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1424-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1424.html" />
      <reference source="CVE" ref_id="CVE-2011-2939" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2939.html" />
      <reference source="CVE" ref_id="CVE-2011-3597" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3597.html" />
    <description>Perl is a high-level programming language commonly used for system
administration utilities and web programming.

A heap-based buffer overflow flaw was found in the way Perl decoded Unicode
strings. An attacker could create a malicious Unicode string that, when
decoded by a Perl program, would cause the program to crash or,
potentially, execute arbitrary code with the permissions of the user
running the program. (CVE-2011-2939)

It was found that the "new" constructor of the Digest module used its
argument as part of the string expression passed to the eval() function. An
attacker could possibly use this flaw to execute arbitrary Perl code with
the privileges of a Perl program that uses untrusted input as an argument
to the constructor. (CVE-2011-3597)

All Perl users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running Perl programs must
be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-03" />
        <updated date="2011-11-03" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2939.html">CVE-2011-2939</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3597.html">CVE-2011-3597</cve>
        <bugzilla href="http://bugzilla.redhat.com/731246" id="731246">CVE-2011-2939 Perl decode_xs heap-based buffer overflow</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743010" id="743010">CVE-2011-3597 Perl Digest improper control of generation of code</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424047" comment="perl-CPANPLUS is earlier than 4:0.88-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558082" comment="perl-CPANPLUS is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424045" comment="perl-Compress-Raw-Zlib is earlier than 4:2.023-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558056" comment="perl-Compress-Raw-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424041" comment="perl-Log-Message is earlier than 4:0.02-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558070" comment="perl-Log-Message is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424029" comment="perl-IO-Zlib is earlier than 4:1.09-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558052" comment="perl-IO-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424025" comment="perl-Module-Build is earlier than 4:0.3500-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558022" comment="perl-Module-Build is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424009" comment="perl-Module-CoreList is earlier than 4:2.18-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558060" comment="perl-Module-CoreList is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424089" comment="perl-Digest-SHA is earlier than 4:5.47-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558026" comment="perl-Digest-SHA is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424073" comment="perl-suidperl is earlier than 4:5.10.1-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558062" comment="perl-suidperl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424067" comment="perl-ExtUtils-CBuilder is earlier than 4:0.27-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558030" comment="perl-ExtUtils-CBuilder is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424049" comment="perl-libs is earlier than 4:5.10.1-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558078" comment="perl-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424037" comment="perl-Term-UI is earlier than 4:0.20-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558050" comment="perl-Term-UI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424013" comment="perl-devel is earlier than 4:5.10.1-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558040" comment="perl-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424011" comment="perl-Package-Constants is earlier than 4:0.02-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558090" comment="perl-Package-Constants is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424063" comment="perl-Test-Simple is earlier than 4:0.92-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558014" comment="perl-Test-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424017" comment="perl-Parse-CPAN-Meta is earlier than 4:1.40-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558054" comment="perl-Parse-CPAN-Meta is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424091" comment="perl-Time-Piece is earlier than 4:1.15-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558036" comment="perl-Time-Piece is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424075" comment="perl-Pod-Escapes is earlier than 4:1.04-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558034" comment="perl-Pod-Escapes is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424069" comment="perl-Object-Accessor is earlier than 4:0.34-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558044" comment="perl-Object-Accessor is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424085" comment="perl-CPAN is earlier than 4:1.9402-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558068" comment="perl-CPAN is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424065" comment="perl-IPC-Cmd is earlier than 4:0.56-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558016" comment="perl-IPC-Cmd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424053" comment="perl-Pod-Simple is earlier than 4:3.13-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558042" comment="perl-Pod-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424033" comment="perl-IO-Compress-Zlib is earlier than 4:2.020-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558058" comment="perl-IO-Compress-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424023" comment="perl-Module-Load-Conditional is earlier than 4:0.30-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558008" comment="perl-Module-Load-Conditional is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424015" comment="perl-Compress-Zlib is earlier than 4:2.020-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558066" comment="perl-Compress-Zlib is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424007" comment="perl-Archive-Extract is earlier than 4:0.38-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558084" comment="perl-Archive-Extract is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424077" comment="perl-ExtUtils-MakeMaker is earlier than 4:6.55-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558074" comment="perl-ExtUtils-MakeMaker is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424055" comment="perl-version is earlier than 4:0.77-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558024" comment="perl-version is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424051" comment="perl-ExtUtils-Embed is earlier than 4:1.28-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558076" comment="perl-ExtUtils-Embed is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424043" comment="perl-Locale-Maketext-Simple is earlier than 4:0.18-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558048" comment="perl-Locale-Maketext-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424039" comment="perl-ExtUtils-ParseXS is earlier than 4:2.2003.0-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558032" comment="perl-ExtUtils-ParseXS is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424005" comment="perl is earlier than 4:5.10.1-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558006" comment="perl is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424031" comment="perl-Module-Pluggable is earlier than 4:3.90-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558086" comment="perl-Module-Pluggable is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424027" comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558020" comment="perl-Time-HiRes is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424083" comment="perl-Archive-Tar is earlier than 4:1.58-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558018" comment="perl-Archive-Tar is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424021" comment="perl-IO-Compress-Base is earlier than 4:2.020-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558046" comment="perl-IO-Compress-Base is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424087" comment="perl-Module-Load is earlier than 4:0.16-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558038" comment="perl-Module-Load is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424081" comment="perl-CGI is earlier than 4:3.51-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558072" comment="perl-CGI is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424079" comment="perl-Params-Check is earlier than 4:0.26-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558028" comment="perl-Params-Check is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424071" comment="perl-core is earlier than 4:5.10.1-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558092" comment="perl-core is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424061" comment="perl-Log-Message-Simple is earlier than 4:0.04-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558088" comment="perl-Log-Message-Simple is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424059" comment="perl-File-Fetch is earlier than 4:0.26-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558080" comment="perl-File-Fetch is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424057" comment="perl-Module-Loaded is earlier than 4:0.02-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558010" comment="perl-Module-Loaded is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424035" comment="perl-parent is earlier than 4:0.221-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558064" comment="perl-parent is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111424019" comment="perl-Test-Harness is earlier than 4:3.17-119.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110558012" comment="perl-Test-Harness is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111434" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1434: acroread security update (Critical)</title>
    <affected family="unix">
      <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
      <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1434.html" />
      <reference source="CVE" ref_id="CVE-2011-2094" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2094.html" />
      <reference source="CVE" ref_id="CVE-2011-2095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2095.html" />
      <reference source="CVE" ref_id="CVE-2011-2096" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2096.html" />
      <reference source="CVE" ref_id="CVE-2011-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2097.html" />
      <reference source="CVE" ref_id="CVE-2011-2098" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2098.html" />
      <reference source="CVE" ref_id="CVE-2011-2099" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2099.html" />
      <reference source="CVE" ref_id="CVE-2011-2101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2101.html" />
      <reference source="CVE" ref_id="CVE-2011-2104" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2104.html" />
      <reference source="CVE" ref_id="CVE-2011-2105" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2105.html" />
      <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html" />
      <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html" />
      <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html" />
      <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html" />
      <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html" />
      <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html" />
      <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html" />
      <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html" />
      <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html" />
      <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html" />
      <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html" />
      <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html" />
      <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html" />
      <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html" />
      <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html" />
      <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html" />
      <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html" />
      <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html" />
      <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html" />
      <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html" />
      <reference source="CVE" ref_id="CVE-2011-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2431.html" />
      <reference source="CVE" ref_id="CVE-2011-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2432.html" />
      <reference source="CVE" ref_id="CVE-2011-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2433.html" />
      <reference source="CVE" ref_id="CVE-2011-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2434.html" />
      <reference source="CVE" ref_id="CVE-2011-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2435.html" />
      <reference source="CVE" ref_id="CVE-2011-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2436.html" />
      <reference source="CVE" ref_id="CVE-2011-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2437.html" />
      <reference source="CVE" ref_id="CVE-2011-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2438.html" />
      <reference source="CVE" ref_id="CVE-2011-2439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2439.html" />
      <reference source="CVE" ref_id="CVE-2011-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2440.html" />
      <reference source="CVE" ref_id="CVE-2011-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2442.html" />
      <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html" />
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

This update fixes multiple security flaws in Adobe Reader. These flaws are
detailed on the Adobe security page APSB11-24, listed in the References
section. A specially-crafted PDF file could cause Adobe Reader to crash or,
potentially, execute arbitrary code as the user running Adobe Reader when
opened. (CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434,
CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439,
CVE-2011-2440, CVE-2011-2442)

This update also fixes multiple security flaws in Adobe Flash Player
embedded in Adobe Reader. These flaws are detailed on the Adobe security
pages APSB11-21 and APSB11-26, listed in the References section.

A PDF file with an embedded, specially-crafted SWF file could cause Adobe
Reader to crash or, potentially, execute arbitrary code as the user running
Adobe Reader when opened. (CVE-2011-2130, CVE-2011-2134, CVE-2011-2135,
CVE-2011-2136, CVE-2011-2137, CVE-2011-2138, CVE-2011-2139, CVE-2011-2140,
CVE-2011-2414, CVE-2011-2415, CVE-2011-2416, CVE-2011-2417, CVE-2011-2424,
CVE-2011-2425, CVE-2011-2426, CVE-2011-2427, CVE-2011-2428, CVE-2011-2430)

A flaw in Adobe Flash Player could allow an attacker to conduct cross-site
scripting (XSS) attacks if a victim were tricked into visiting a
specially-crafted web page. (CVE-2011-2444)

This update also fixes an information disclosure flaw in Adobe Flash
Player. (CVE-2011-2429)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 9.4.6, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2094.html">CVE-2011-2094</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2095.html">CVE-2011-2095</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2096.html">CVE-2011-2096</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2097.html">CVE-2011-2097</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2098.html">CVE-2011-2098</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2099.html">CVE-2011-2099</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2101.html">CVE-2011-2101</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2104.html">CVE-2011-2104</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2105.html">CVE-2011-2105</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2107.html">CVE-2011-2107</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2130.html">CVE-2011-2130</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2134.html">CVE-2011-2134</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2135.html">CVE-2011-2135</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2136.html">CVE-2011-2136</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2137.html">CVE-2011-2137</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2138.html">CVE-2011-2138</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2139.html">CVE-2011-2139</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2140.html">CVE-2011-2140</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2414.html">CVE-2011-2414</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2415.html">CVE-2011-2415</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2416.html">CVE-2011-2416</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2417.html">CVE-2011-2417</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2424.html">CVE-2011-2424</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2425.html">CVE-2011-2425</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2426.html">CVE-2011-2426</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2427.html">CVE-2011-2427</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2428.html">CVE-2011-2428</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2429.html">CVE-2011-2429</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2430.html">CVE-2011-2430</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2431.html">CVE-2011-2431</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2432.html">CVE-2011-2432</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2433.html">CVE-2011-2433</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2434.html">CVE-2011-2434</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2435.html">CVE-2011-2435</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2436.html">CVE-2011-2436</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2437.html">CVE-2011-2437</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2438.html">CVE-2011-2438</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2439.html">CVE-2011-2439</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2440.html">CVE-2011-2440</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2442.html">CVE-2011-2442</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2444.html">CVE-2011-2444</cve>
        <bugzilla href="http://bugzilla.redhat.com/729497" id="729497">CVE-2011-2130 CVE-2011-2134 CVE-2011-2135 CVE-2011-2136 CVE-2011-2137 CVE-2011-2138 CVE-2011-2139 CVE-2011-2140 CVE-2011-2414 CVE-2011-2415 CVE-2011-2416 CVE-2011-2417 CVE-2011-2425 flash-plugin: multiple arbitrary code execution flaws (APSB-11-21)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740201" id="740201">CVE-2011-2444 acroread, flash-plugin: Cross-site scripting vulnerability fixed in APSB11-26</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740204" id="740204">CVE-2011-2429 acroread, flash-plugin: security control bypass information disclosure fixed in APSB11-26</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740388" id="740388">CVE-2011-2426 CVE-2011-2427 CVE-2011-2428 CVE-2011-2430 acroread, flash-plugin: critical flaws fixed in APSB11-26</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/749381" id="749381">acroread: multiple code execution flaws (APSB11-24)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_extras</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111434004" comment="acroread-plugin is earlier than 0:9.4.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111434002" comment="acroread is earlier than 0:9.4.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111434012" comment="acroread-plugin is earlier than 0:9.4.6-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301013" comment="acroread-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111434010" comment="acroread is earlier than 0:9.4.6-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110301011" comment="acroread is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111437" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1437: firefox security update (Critical)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
      <platform>Red Hat Enterprise Linux 5</platform>
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1437-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1437.html" />
      <reference source="CVE" ref_id="CVE-2011-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3647.html" />
      <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html" />
      <reference source="CVE" ref_id="CVE-2011-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3650.html" />
    <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the way Firefox handled certain add-ons. A web page
containing malicious content could cause an add-on to grant itself full
browser privileges, which could lead to arbitrary code execution with the
privileges of the user running Firefox. (CVE-2011-3647)

A cross-site scripting (XSS) flaw was found in the way Firefox handled
certain multibyte character sets. A web page containing malicious content
could cause Firefox to run JavaScript code with the permissions of a
different website. (CVE-2011-3648)

A flaw was found in the way Firefox handled large JavaScript scripts. A web
page containing malicious JavaScript could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-3650)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.6.24. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.24, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3647.html">CVE-2011-3647</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3648.html">CVE-2011-3648</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3650.html">CVE-2011-3650</cve>
        <bugzilla href="http://bugzilla.redhat.com/751931" id="751931">CVE-2011-3647 Mozilla: Security problem with loadSubScript on 1.9.2 branch (MFSA 2011-46)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751932" id="751932">CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751933" id="751933">CVE-2011-3650 Mozilla: crash while profiling page with many functions (MFSA 2011-49)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111437002" comment="firefox is earlier than 0:3.6.24-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310024" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437005" comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437007" comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437009" comment="firefox is earlier than 0:3.6.24-3.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310007" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437015" comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310014" comment="xulrunner is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437017" comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310016" comment="xulrunner-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111437019" comment="firefox is earlier than 0:3.6.24-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110310020" comment="firefox is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111438" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1438: thunderbird security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
      <platform>Red Hat Enterprise Linux 5</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1438-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1438.html" />
      <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html" />
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A cross-site scripting (XSS) flaw was found in the way Thunderbird handled
certain multibyte character sets. Malicious, remote content could cause
Thunderbird to run JavaScript code with the permissions of different remote
content. (CVE-2011-3648)

Note: This issue cannot be exploited by a specially-crafted HTML mail
message as JavaScript is disabled by default for mail messages. It could be
exploited another way in Thunderbird, for example, when viewing the full
remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3648.html">CVE-2011-3648</cve>
        <bugzilla href="http://bugzilla.redhat.com/751932" id="751932">CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_productivity</cpe>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111438002" comment="thunderbird is earlier than 0:1.5.0.12-45.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111438005" comment="thunderbird is earlier than 0:2.0.0.24-27.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110312003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111439" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1439: thunderbird security update (Critical)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1439-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1439.html" />
      <reference source="CVE" ref_id="CVE-2011-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3647.html" />
      <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html" />
      <reference source="CVE" ref_id="CVE-2011-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3650.html" />
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the way Thunderbird handled certain add-ons. Malicious,
remote content could cause an add-on to elevate its privileges, which could
lead to arbitrary code execution with the privileges of the user running
Thunderbird. (CVE-2011-3647)

A cross-site scripting (XSS) flaw was found in the way Thunderbird handled
certain multibyte character sets. Malicious, remote content could cause
Thunderbird to run JavaScript code with the permissions of different
remote content. (CVE-2011-3648)

A flaw was found in the way Thunderbird handled large JavaScript scripts.
Malicious, remote content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird.
(CVE-2011-3650)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3647.html">CVE-2011-3647</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3648.html">CVE-2011-3648</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3650.html">CVE-2011-3650</cve>
        <bugzilla href="http://bugzilla.redhat.com/751931" id="751931">CVE-2011-3647 Mozilla: Security problem with loadSubScript on 1.9.2 branch (MFSA 2011-46)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751932" id="751932">CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751933" id="751933">CVE-2011-3650 Mozilla: crash while profiling page with many functions (MFSA 2011-49)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111439005" comment="thunderbird is earlier than 0:3.1.16-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110311006" comment="thunderbird is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111440" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1440: seamonkey security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1440-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1440.html" />
      <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html" />
    <description>SeaMonkey is an open source web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A cross-site scripting (XSS) flaw was found in the way SeaMonkey handled
certain multibyte character sets. A web page containing malicious content
could cause SeaMonkey to run JavaScript code with the permissions of a
different website. (CVE-2011-3648)
 
All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3648.html">CVE-2011-3648</cve>
        <bugzilla href="http://bugzilla.redhat.com/751932" id="751932">CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440010" comment="seamonkey-mail is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313009" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440002" comment="seamonkey is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440006" comment="seamonkey-chat is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313005" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111440004" comment="seamonkey-devel is earlier than 0:1.0.9-77.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110313007" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111441" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1441: icedtea-web security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1441-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1441.html" />
      <reference source="CVE" ref_id="CVE-2011-3377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3377.html" />
    <description>The IcedTea-Web project provides a Java web browser plug-in and an
implementation of Java Web Start, which is based on the Netx project. It
also contains a configuration tool for managing deployment settings for the
plug-in and Web Start implementations.

A flaw was found in the same-origin policy implementation in the
IcedTea-Web browser plug-in. A malicious Java applet could use this flaw to
open network connections to hosts other than the originating host,
violating the same-origin policy. (CVE-2011-3377)

All IcedTea-Web users should upgrade to these updated packages, which
upgrade IcedTea-Web to version 1.0.6 to correct this issue. Web browsers
using the IcedTea-Web browser plug-in must be restarted for this update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-08" />
        <updated date="2011-11-08" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3377.html">CVE-2011-3377</cve>
        <bugzilla href="http://bugzilla.redhat.com/742515" id="742515">CVE-2011-3377 IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111441007" comment="icedtea-web-javadoc is earlier than 0:1.0.6-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111100008" comment="icedtea-web-javadoc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111441005" comment="icedtea-web is earlier than 0:1.0.6-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111100006" comment="icedtea-web is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111444" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1444: nss security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
      <platform>Red Hat Enterprise Linux 4</platform>
      <platform>Red Hat Enterprise Linux 5</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1444-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1444.html" />
    <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate
Certificate Authority (CA) issued HTTPS certificates with weak keys. This
update renders any HTTPS certificates signed by that CA as untrusted. This
covers all uses of the certificates, including SSL, S/MIME, and code
signing. Note: Digicert Sdn. Bhd. is not the same company as found at
digicert.com. (BZ#751366)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

This update also fixes the following bug on Red Hat Enterprise Linux 5:

* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat
Enterprise Linux 5 resulted in file descriptors leaking each time the
Apache HTTP Server was restarted with the "service httpd reload" command.
This could have prevented the Apache HTTP Server from functioning properly
if all available file descriptors were consumed. (BZ#743508)

For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to
version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to
version 4.8.8 and nss-util to version 3.12.10 on Red Hat
Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,
BZ#735973)

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect. In addition, on Red Hat
Enterprise Linux 6, applications using NSPR and nss-util must also be
restarted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-09" />
        <updated date="2011-11-09" />
        <bugzilla href="http://bugzilla.redhat.com/735972" id="735972">Update nss to 3.12.10</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/735973" id="735973">Update nss-util to 3.12.10</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736272" id="736272">Update nspr to 4.8.8</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743508" id="743508">File descriptor leak after "service httpd reload"</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751366" id="751366">Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority from nss</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444002" comment="nss is earlier than 0:3.12.10-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472026" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444006" comment="nss-tools is earlier than 0:3.12.10-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472030" comment="nss-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444004" comment="nss-devel is earlier than 0:3.12.10-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472028" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444009" comment="nss is earlier than 0:3.12.10-7.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472003" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444015" comment="nss-tools is earlier than 0:3.12.10-7.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472009" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444013" comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472007" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444011" comment="nss-devel is earlier than 0:3.12.10-7.el5_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472005" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444021" comment="nss is earlier than 0:3.12.10-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472015" comment="nss is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444029" comment="nss-tools is earlier than 0:3.12.10-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472019" comment="nss-tools is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444027" comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472017" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444025" comment="nss-devel is earlier than 0:3.12.10-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472023" comment="nss-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444023" comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110472021" comment="nss-sysinit is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444033" comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111444034" comment="nspr-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444031" comment="nspr is earlier than 0:4.8.8-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111444032" comment="nspr is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444035" comment="nss-util is earlier than 0:3.12.10-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111444036" comment="nss-util is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111444037" comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111444038" comment="nss-util-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111445" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1445: flash-plugin security update (Critical)</title>
    <affected family="unix">
      <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
      <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1445-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1445.html" />
      <reference source="CVE" ref_id="CVE-2011-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2445.html" />
      <reference source="CVE" ref_id="CVE-2011-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2450.html" />
      <reference source="CVE" ref_id="CVE-2011-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2451.html" />
      <reference source="CVE" ref_id="CVE-2011-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2452.html" />
      <reference source="CVE" ref_id="CVE-2011-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2453.html" />
      <reference source="CVE" ref_id="CVE-2011-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2454.html" />
      <reference source="CVE" ref_id="CVE-2011-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2455.html" />
      <reference source="CVE" ref_id="CVE-2011-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2456.html" />
      <reference source="CVE" ref_id="CVE-2011-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2457.html" />
      <reference source="CVE" ref_id="CVE-2011-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2459.html" />
      <reference source="CVE" ref_id="CVE-2011-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2460.html" />
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed on the Adobe security page APSB11-28, listed
in the References section.

Multiple security flaws were found in the way flash-plugin displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
potentially, execute arbitrary code when the victim loaded a page
containing the specially-crafted SWF content. (CVE-2011-2445,
CVE-2011-2450, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454,
CVE-2011-2455, CVE-2011-2456, CVE-2011-2457, CVE-2011-2459, CVE-2011-2460)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.183.11.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-11" />
        <updated date="2011-11-11" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2445.html">CVE-2011-2445</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2450.html">CVE-2011-2450</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2451.html">CVE-2011-2451</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2452.html">CVE-2011-2452</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2453.html">CVE-2011-2453</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2454.html">CVE-2011-2454</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2455.html">CVE-2011-2455</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2456.html">CVE-2011-2456</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2457.html">CVE-2011-2457</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2459.html">CVE-2011-2459</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2460.html">CVE-2011-2460</cve>
        <bugzilla href="http://bugzilla.redhat.com/752983" id="752983">flash-plugin: mulitple code execution flaws (APSB11-28)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_extras</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111445002" comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110372003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111445008" comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110206006" comment="flash-plugin is signed with Red Hat redhatrelease2 key" />
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111455" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1455: freetype security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
      <platform>Red Hat Enterprise Linux 5</platform>
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1455.html" />
      <reference source="CVE" ref_id="CVE-2011-3439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3439.html" />
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.

Multiple input validation flaws were found in the way FreeType processed
CID-keyed fonts. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3439)

Note: These issues only affected the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-16" />
        <updated date="2011-11-16" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3439.html">CVE-2011-3439</cve>
        <bugzilla href="http://bugzilla.redhat.com/753799" id="753799">CVE-2011-3439 freetype: Multiple security flaws when loading CID-keyed Type 1 fonts</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455008" comment="freetype-demos is earlier than 0:2.1.9-21.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161007" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455006" comment="freetype-utils is earlier than 0:2.1.9-21.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161005" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455004" comment="freetype-devel is earlier than 0:2.1.9-21.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161009" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455002" comment="freetype is earlier than 0:2.1.9-21.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111161003" comment="freetype is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455013" comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402014" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455015" comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402016" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455011" comment="freetype is earlier than 0:2.2.1-28.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111402012" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455023" comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085008" comment="freetype-demos is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455025" comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085010" comment="freetype-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111455021" comment="freetype is earlier than 0:2.3.11-6.el6_1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111085006" comment="freetype is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111458" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1458: bind security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 5</platform>
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1458-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1458.html" />
      <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html" />
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-17" />
        <updated date="2011-11-17" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4313.html">CVE-2011-4313</cve>
        <bugzilla href="http://bugzilla.redhat.com/754398" id="754398">CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458016" comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458017" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458010" comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458011" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458008" comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458009" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458014" comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458015" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458012" comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458013" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458002" comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458006" comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458007" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458004" comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111458005" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458032" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845019" comment="bind-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458028" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845027" comment="bind-chroot is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458030" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845021" comment="bind-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458024" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845023" comment="bind-sdb is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458022" comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845017" comment="bind is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111458026" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845025" comment="bind-libs is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111459" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1459: bind97 security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 5</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1459.html" />
      <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html" />
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind97 are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-17" />
        <updated date="2011-11-17" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4313.html">CVE-2011-4313</cve>
        <bugzilla href="http://bugzilla.redhat.com/754398" id="754398">CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111459010" comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845011" comment="bind97-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111459004" comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845009" comment="bind97-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111459008" comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845005" comment="bind97-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111459002" comment="bind97 is earlier than 32:9.7.0-6.P2.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845003" comment="bind97 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111459006" comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110845007" comment="bind97-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111465" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1465: kernel security and bug fix update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1465.html" />
      <reference source="CVE" ref_id="CVE-2011-1162" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1162.html" />
      <reference source="CVE" ref_id="CVE-2011-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1577.html" />
      <reference source="CVE" ref_id="CVE-2011-2494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2494.html" />
      <reference source="CVE" ref_id="CVE-2011-2699" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2699.html" />
      <reference source="CVE" ref_id="CVE-2011-2905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2905.html" />
      <reference source="CVE" ref_id="CVE-2011-3188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3188.html" />
      <reference source="CVE" ref_id="CVE-2011-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3191.html" />
      <reference source="CVE" ref_id="CVE-2011-3353" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3353.html" />
      <reference source="CVE" ref_id="CVE-2011-3359" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3359.html" />
      <reference source="CVE" ref_id="CVE-2011-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3363.html" />
      <reference source="CVE" ref_id="CVE-2011-3593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3593.html" />
      <reference source="CVE" ref_id="CVE-2011-4326" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4326.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* IPv6 fragment identification value generation could allow a remote
attacker to disrupt a target system's networking, preventing legitimate
users from accessing its services. (CVE-2011-2699, Important)

* A signedness issue was found in the Linux kernel's CIFS (Common Internet
File System) implementation. A malicious CIFS server could send a
specially-crafted response to a directory read request that would result in
a denial of service or privilege escalation on a system that has a CIFS
share mounted. (CVE-2011-3191, Important)

* A flaw was found in the way the Linux kernel handled fragmented IPv6 UDP
datagrams over the bridge with UDP Fragmentation Offload (UFO)
functionality on. A remote attacker could use this flaw to cause a denial
of service. (CVE-2011-4326, Important)

* The way IPv4 and IPv6 protocol sequence numbers and fragment IDs were
generated could allow a man-in-the-middle attacker to inject packets and
possibly hijack connections. Protocol sequence numbers and fragment IDs are
now more random. (CVE-2011-3188, Moderate)

* A buffer overflow flaw was found in the Linux kernel's FUSE (Filesystem
in Userspace) implementation. A local user in the fuse group who has access
to mount a FUSE file system could use this flaw to cause a denial of
service. (CVE-2011-3353, Moderate)

* A flaw was found in the b43 driver in the Linux kernel. If a system had
an active wireless interface that uses the b43 driver, an attacker able to
send a specially-crafted frame to that interface could cause a denial of
service. (CVE-2011-3359, Moderate)

* A flaw was found in the way CIFS shares with DFS referrals at their root
were handled. An attacker on the local network who is able to deploy a
malicious CIFS server could create a CIFS network share that, when mounted,
would cause the client system to crash. (CVE-2011-3363, Moderate)

* A flaw was found in the way the Linux kernel handled VLAN 0 frames with
the priority tag set. When using certain network drivers, an attacker on
the local network could use this flaw to cause a denial of service.
(CVE-2011-3593, Moderate)

* A flaw in the way memory containing security-related data was handled in
tpm_read() could allow a local, unprivileged user to read the results of a
previously run TPM command. (CVE-2011-1162, Low)

* A heap overflow flaw was found in the Linux kernel's EFI GUID Partition
Table (GPT) implementation. A local attacker could use this flaw to cause
a denial of service by mounting a disk that contains specially-crafted
partition tables. (CVE-2011-1577, Low)

* The I/O statistics from the taskstats subsystem could be read without
any restrictions. A local, unprivileged user could use this flaw to gather
confidential information, such as the length of a password used in a
process. (CVE-2011-2494, Low)

* It was found that the perf tool, a part of the Linux kernel's Performance
Events implementation, could load its configuration file from the current
working directory. If a local user with access to the perf tool were
tricked into running perf in a directory that contains a specially-crafted
configuration file, it could cause perf to overwrite arbitrary files and
directories accessible to that user. (CVE-2011-2905, Low)

Red Hat would like to thank Fernando Gont for reporting CVE-2011-2699;
Darren Lavender for reporting CVE-2011-3191; Dan Kaminsky for reporting
CVE-2011-3188; Yogesh Sharma for reporting CVE-2011-3363; Gideon Naim for
reporting CVE-2011-3593; Peter Huewe for reporting CVE-2011-1162; Timo
Warns for reporting CVE-2011-1577; and Vasiliy Kulikov of Openwall for
reporting CVE-2011-2494.

This update also fixes various bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-22" />
        <updated date="2011-11-22" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1162.html">CVE-2011-1162</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1577.html">CVE-2011-1577</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2494.html">CVE-2011-2494</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2699.html">CVE-2011-2699</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2905.html">CVE-2011-2905</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3188.html">CVE-2011-3188</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3191.html">CVE-2011-3191</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3353.html">CVE-2011-3353</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3359.html">CVE-2011-3359</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3363.html">CVE-2011-3363</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3593.html">CVE-2011-3593</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4326.html">CVE-2011-4326</cve>
        <bugzilla href="http://bugzilla.redhat.com/695976" id="695976">CVE-2011-1577 kernel: corrupted GUID partition tables can cause kernel oops</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/716842" id="716842">CVE-2011-2494 kernel: taskstats io infoleak</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723429" id="723429">CVE-2011-2699 kernel: ipv6: make fragment identifications less predictable</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729808" id="729808">CVE-2011-2905 kernel: perf tools: may parse user-controlled configuration file</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732629" id="732629">CVE-2011-1162 kernel: tpm: infoleak</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732658" id="732658">CVE-2011-3188 kernel: net: improve sequence number generation</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732869" id="732869">CVE-2011-3191 kernel: cifs: signedness issue in CIFSFindNext()</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736761" id="736761">CVE-2011-3353 kernel: fuse: check size of FUSE_NOTIFY_INVAL_ENTRY message</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738202" id="738202">CVE-2011-3359 kernel: b43: allocate receive buffers big enough for max frame len + offset</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738291" id="738291">CVE-2011-3363 kernel: cifs: always do is_path_accessible check in cifs_mount</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740352" id="740352">make guest mode entry to be rcu quiescent state [rhel-6.1.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741166" id="741166">enclosure fix [rhel-6.1.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/742846" id="742846">CVE-2011-3593 kernel: vlan: fix panic when handling priority tagged frames</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743807" id="743807">igb: failed to activate WOL on 2nd LAN port on i350 [rhel-6.1.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744811" id="744811">Non-responsive scsi target leads to excessive scsi recovery and dm-mp failover time [rhel-6.1.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/748808" id="748808">Host got crash when guest running netperf client with UDP_STREAM protocol with IPV6 [rhel-6.1.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/755584" id="755584">CVE-2011-4326 kernel: wrong headroom check in udp6_ufo_fragment()</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465015" comment="perf is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007022" comment="perf is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465009" comment="kernel-headers is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007010" comment="kernel-headers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465005" comment="kernel is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007006" comment="kernel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465023" comment="kernel-doc is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007026" comment="kernel-doc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465025" comment="kernel-firmware is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007024" comment="kernel-firmware is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465011" comment="kernel-devel is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007014" comment="kernel-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465021" comment="kernel-kdump is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007018" comment="kernel-kdump is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465017" comment="kernel-debug is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007012" comment="kernel-debug is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465013" comment="kernel-debug-devel is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007016" comment="kernel-debug-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465019" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007020" comment="kernel-kdump-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111465007" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.21.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007008" comment="kernel-bootwrapper is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111478" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
      <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
      <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1478.html" />
      <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html" />
      <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html" />
      <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html" />
      <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html" />
      <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html" />
      <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html" />
      <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html" />
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM "Security alerts" page,
listed in the References section. (CVE-2011-3545, CVE-2011-3547,
CVE-2011-3548, CVE-2011-3549, CVE-2011-3552, CVE-2011-3554, CVE-2011-3556)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR13 Java release. All running instances
of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-24" />
        <updated date="2011-11-24" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3545.html">CVE-2011-3545</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3547.html">CVE-2011-3547</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3548.html">CVE-2011-3548</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3549.html">CVE-2011-3549</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3552.html">CVE-2011-3552</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3554.html">CVE-2011-3554</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3556.html">CVE-2011-3556</cve>
        <bugzilla href="http://bugzilla.redhat.com/745387" id="745387">CVE-2011-3547 OpenJDK: InputStream skip() information leak (Networking/IO, 7000600)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745397" id="745397">CVE-2011-3552 OpenJDK: excessive default UDP socket limit under SecurityManager (Networking, 7032417)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745447" id="745447">CVE-2011-3554 OpenJDK: insufficient pack200 JAR files uncompress error checks (Runtime, 7057857)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745459" id="745459">CVE-2011-3556 OpenJDK: RMI DGC server remote code execution (RMI, 7077466)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745473" id="745473">CVE-2011-3548 OpenJDK: mutable static AWTKeyStroke.ctor (AWT, 7019773)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747191" id="747191">CVE-2011-3545 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Sound)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/747198" id="747198">CVE-2011-3549 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Swing)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_extras</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478016" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169005" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478008" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478012" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169007" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478006" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478010" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169011" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169017" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478014" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169009" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478022" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169023" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478030" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169027" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478026" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169031" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478024" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169033" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478034" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169025" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478032" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169029" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111478028" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110169035" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111479" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1479: kernel security, bug fix, and enhancement update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 5</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1479.html" />
      <reference source="CVE" ref_id="CVE-2011-1162" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1162.html" />
      <reference source="CVE" ref_id="CVE-2011-1898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1898.html" />
      <reference source="CVE" ref_id="CVE-2011-2203" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2203.html" />
      <reference source="CVE" ref_id="CVE-2011-2494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2494.html" />
      <reference source="CVE" ref_id="CVE-2011-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3363.html" />
      <reference source="CVE" ref_id="CVE-2011-4110" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4110.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Using PCI passthrough without interrupt remapping support allowed Xen
hypervisor guests to generate MSI interrupts and thus potentially inject
traps. A privileged guest user could use this flaw to crash the host or
possibly escalate their privileges on the host. The fix for this issue can
prevent PCI passthrough working and guests starting. Refer to Red Hat
Bugzilla bug 715555 for details. (CVE-2011-1898, Important)

* A flaw was found in the way CIFS (Common Internet File System) shares
with DFS referrals at their root were handled. An attacker on the local
network who is able to deploy a malicious CIFS server could create a CIFS
network share that, when mounted, would cause the client system to crash.
(CVE-2011-3363, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
key management facility handled user-defined key types. A local,
unprivileged user could use the keyctl utility to cause a denial of
service. (CVE-2011-4110, Moderate)

* A flaw in the way memory containing security-related data was handled in
tpm_read() could allow a local, unprivileged user to read the results of a
previously run TPM command. (CVE-2011-1162, Low)

* A NULL pointer dereference flaw was found in the Linux kernel's HFS file
system implementation. A local attacker could use this flaw to cause a
denial of service by mounting a disk that contains a specially-crafted HFS
file system with a corrupted MDB extent record. (CVE-2011-2203, Low)

* The I/O statistics from the taskstats subsystem could be read without
any restrictions. A local, unprivileged user could use this flaw to gather
confidential information, such as the length of a password used in a
process. (CVE-2011-2494, Low)

Red Hat would like to thank Yogesh Sharma for reporting CVE-2011-3363;
Peter Huewe for reporting CVE-2011-1162; Clement Lecigne for reporting
CVE-2011-2203; and Vasiliy Kulikov of Openwall for reporting CVE-2011-2494.

This update also fixes several bugs and adds one enhancement. Documentation
for these changes will be available shortly from the Technical Notes
document linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues, and fix the bugs and add the enhancement
noted in the Technical Notes. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-29" />
        <updated date="2011-11-29" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1162.html">CVE-2011-1162</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1898.html">CVE-2011-1898</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2203.html">CVE-2011-2203</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-2494.html">CVE-2011-2494</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3363.html">CVE-2011-3363</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4110.html">CVE-2011-4110</cve>
        <bugzilla href="http://bugzilla.redhat.com/712774" id="712774">CVE-2011-2203 kernel: hfs_find_init() sb->ext_tree NULL pointer dereference</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/715555" id="715555">CVE-2011-1898 virt: VT-d (PCI passthrough) MSI trap injection</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/716842" id="716842">CVE-2011-2494 kernel: taskstats io infoleak</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732629" id="732629">CVE-2011-1162 kernel: tpm: infoleak</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738291" id="738291">CVE-2011-3363 kernel: cifs: always do is_path_accessible check in cifs_mount</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741273" id="741273">Non-responsive scsi target leads to excessive scsi recovery and dm-mp failover time [rhel-5.7.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745726" id="745726">Host crash when pass-through fails [rhel-5.7.z]</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/751297" id="751297">CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key type</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479004" comment="kernel-headers is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479002" comment="kernel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479024" comment="kernel-doc is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479012" comment="kernel-devel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479016" comment="kernel-kdump is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479008" comment="kernel-xen-devel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479006" comment="kernel-debug is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479010" comment="kernel-debug-devel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004015" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479020" comment="kernel-PAE is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004023" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479022" comment="kernel-PAE-devel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004021" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479018" comment="kernel-kdump-devel is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111479014" comment="kernel-xen is earlier than 0:2.6.18-274.12.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110004007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111496" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1496: bind security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1496-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1496.html" />
      <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html" />
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was discovered in the way BIND handled certain DNS queries, which
caused it to cache an invalid record. A remote attacker could use this
flaw to send repeated queries for this invalid record, causing the
resolvers to exit unexpectedly due to a failed assertion. (CVE-2011-4313)

Users of bind are advised to upgrade to these updated packages, which
resolve this issue. After installing the update, the BIND daemon (named)
will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-11-29" />
        <updated date="2011-11-29" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4313.html">CVE-2011-4313</cve>
        <bugzilla href="http://bugzilla.redhat.com/754398" id="754398">CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111496010" comment="bind-devel is earlier than 20:9.2.4-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111496011" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111496006" comment="bind-chroot is earlier than 20:9.2.4-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111496007" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111496008" comment="bind-utils is earlier than 20:9.2.4-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111496009" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111496002" comment="bind is earlier than 20:9.2.4-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111496003" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111496004" comment="bind-libs is earlier than 20:9.2.4-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111496005" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111506" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1506: Red Hat Enterprise Linux 4 - 3-Month End Of Life Notice (Low)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1506.html" />
    <description>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 4 will end on
February 29, 2012.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 4. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 4
* Red Hat Enterprise Linux ES 4
* Red Hat Enterprise Linux WS 4
* Red Hat Enterprise Linux Extras 4
* Red Hat Desktop 4
* Red Hat Global File System 4
* Red Hat Cluster Suite 4

Customers still running production workloads on Red Hat Enterprise Linux 4
are advised to begin planning the upgrade to Red Hat Enterprise Linux 5 or
6. Active subscribers of Red Hat Enterprise Linux already have access to
all currently maintained versions of Red Hat Enterprise Linux, as part of
their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 4
before its end-of-life date, Red Hat intends to offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: https://access.redhat.com/support/policy/updates/errata/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-12-01" />
        <updated date="2011-12-01" />
        <bugzilla href="http://bugzilla.redhat.com/754175" id="754175">Send Out RHEL 4 3-Month EOL Notice</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111506002" comment="redhat-release is earlier than 0:4Desktop-10.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111506004" comment="redhat-release is earlier than 0:4WS-10.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111506005" comment="redhat-release is earlier than 0:4ES-10.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111506006" comment="redhat-release is earlier than 0:4AS-10.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110219003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111507" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1507: libarchive security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1507.html" />
      <reference source="CVE" ref_id="CVE-2011-1777" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1777.html" />
      <reference source="CVE" ref_id="CVE-2011-1778" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1778.html" />
    <description>The libarchive programming library can create and read several different
streaming archive formats, including GNU tar and cpio. It can also read ISO
9660 CD-ROM images.

Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)

All libarchive users should upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using libarchive must be restarted for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-12-01" />
        <updated date="2011-12-01" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1777.html">CVE-2011-1777</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-1778.html">CVE-2011-1778</cve>
        <bugzilla href="http://bugzilla.redhat.com/705849" id="705849">CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111507007" comment="libarchive-devel is earlier than 0:2.8.3-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111507008" comment="libarchive-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111507005" comment="libarchive is earlier than 0:2.8.3-3.el6_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111507006" comment="libarchive is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111508" version="502" class="patch">
      <metadata>
        <title>RHSA-2011:1508: cyrus-imapd security update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 4</platform>
      <platform>Red Hat Enterprise Linux 5</platform>
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1508-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1508.html" />
      <reference source="CVE" ref_id="CVE-2011-3372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3372.html" />
      <reference source="CVE" ref_id="CVE-2011-3481" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3481.html" />
    <description>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

An authentication bypass flaw was found in the cyrus-imapd NNTP server,
nntpd. A remote user able to use the nntpd service could use this flaw to
read or post newsgroup messages on an NNTP server configured to require
user authentication, without providing valid authentication credentials.
(CVE-2011-3372)

A NULL pointer dereference flaw was found in the cyrus-imapd IMAP server,
imapd. A remote attacker could send a specially-crafted mail message to a
victim that would possibly prevent them from accessing their mail normally,
if they were using an IMAP client that relies on the server threading IMAP
feature. (CVE-2011-3481)

Red Hat would like to thank the Cyrus IMAP project for reporting the
CVE-2011-3372 issue. Upstream acknowledges Stefan Cornelius of Secunia
Research as the original reporter of CVE-2011-3372.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the update, cyrus-imapd will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-12-01" />
        <updated date="2011-12-01" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3372.html">CVE-2011-3372</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3481.html">CVE-2011-3481</cve>
        <bugzilla href="http://bugzilla.redhat.com/738391" id="738391">CVE-2011-3481 cyrus-imapd: NULL pointer dereference via crafted References header in email</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740822" id="740822">CVE-2011-3372 cyrus-imapd: nntpd authentication bypass</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110013016" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508012" comment="cyrus-imapd-murder is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859020" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508002" comment="cyrus-imapd is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859012" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508004" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859022" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508006" comment="cyrus-imapd-devel is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859016" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508010" comment="cyrus-imapd-utils is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859014" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508008" comment="perl-Cyrus is earlier than 0:2.2.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859018" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110004001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508015" comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859003" comment="cyrus-imapd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508019" comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859007" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508021" comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859009" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508017" comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859005" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20110007001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110007004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508027" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859028" comment="cyrus-imapd is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508029" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859032" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111508031" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20110859030" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20111533" version="504" class="patch">
      <metadata>
        <title>RHSA-2011:1533: ipa security and bug fix update (Moderate)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1533-03" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1533.html" />
      <reference source="CVE" ref_id="CVE-2011-3636" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3636.html" />
    <description>Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud based
enterprise environments. It integrates components of the Red Hat Directory
Server, MIT Kerberos, Red Hat Certificate System, NTP and DNS. It provides
web browser and command-line interfaces. Its administration tools allow an
administrator to quickly install, set up, and administer a group of domain
controllers to meet the authentication and identity management requirements
of large scale Linux and UNIX deployments.

A Cross-Site Request Forgery (CSRF) flaw was found in Red Hat Identity
Management. If a remote attacker could trick a user, who was logged into
the management web interface, into visiting a specially-crafted URL, the
attacker could perform Red Hat Identity Management configuration changes
with the privileges of the logged in user. (CVE-2011-3636)

Due to the changes required to fix CVE-2011-3636, client tools will need to
be updated for client systems to communicate with updated Red Hat Identity
Management servers. New client systems will need to have the updated
ipa-client package installed to be enrolled. Already enrolled client
systems will need to have the updated certmonger package installed to be
able to renew their system certificate. Note that system certificates are
valid for two years by default.

Updated ipa-client and certmonger packages for Red Hat Enterprise Linux 6
were released as part of Red Hat Enterprise Linux 6.2. Future updates will
provide updated packages for Red Hat Enterprise Linux 5.

This update includes several bug fixes. Space precludes documenting all of
these changes in this advisory. Users are directed to the Red Hat
Enterprise Linux 6.2 Technical Notes for information on the most
significant of these changes, linked to in the References section.

Users of Red Hat Identity Management should upgrade to these updated
packages, which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-12-05" />
        <updated date="2011-12-06" />
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-3636.html">CVE-2011-3636</cve>
        <bugzilla href="http://bugzilla.redhat.com/680504" id="680504">Can not delete reverse DNS record - interactive CLI mode</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/681978" id="681978">Uninstalling  client if the server is installed should be prevented</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/681979" id="681979">Man page is not clear for ipa-client-install --on-master option usage</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/688925" id="688925">IPA Replica Install Hangs if DS port is unreachable by Master Server</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/689023" id="689023">Can't create password policy via UI</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/689810" id="689810">Inconsistent Error message attempting to add duplicate user</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/690185" id="690185">Uninstalling ipa-client doesn't restore some files, if reinstalled with -force option</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/690473" id="690473">Installing ipa-client indicates DNS is updated for this unknown hostname, but is not on server</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/692144" id="692144">Uninstalling ipa-client doesn't restore sssd.conf, if previously installed with --no-sssd option</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/692950" id="692950">Installing ipa server with --no-reverse option sets up reverse zone</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/693464" id="693464">Make explicit reference to ds-replication package</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/693483" id="693483">Duplicate GIDs</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/693766" id="693766">Mismatch in man page and --help for ipa-server-install</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/693771" id="693771">Preinstall check needed if zonemgr has special char</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/696193" id="696193">Client install fails on ipa-join when master is down, and replica is running.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/696268" id="696268">IPA server install with DNS setup, and with --ip-address cannot resolve hostnames</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/696282" id="696282">Preinstall check needed if subject is not specified in required format</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/697009" id="697009">ipa-replica-manage:  man page and help pages do not match</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/697878" id="697878">IPA server install should wait for Directory Server port to open after every restart of dirsrv</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/698219" id="698219">Uninstalling ipa-client fails, if it joined replica when being installed</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/698421" id="698421">IPA Replica Installing failing on during replication update</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/700586" id="700586">brand name error in ipa-dns-install cli, it still says "FreeIPA Server"</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/701325" id="701325">Unable to Download Certificate with Browser</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/703188" id="703188">TPS: Source rebuild Failures on x86_64 client and workstation</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/703869" id="703869">Managed Entry Configuration Not Setup when installing replica server</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/704012" id="704012">IPA Replica Installation Fails - reverse address doesn't match error</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/705794" id="705794">IPA Replica not started on reboot</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/705800" id="705800">Improve debug logging in ipa-client-install</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/707001" id="707001">Illegal CL input results in NULL csr when requesting external ca.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/707009" id="707009">IPA server with external CA fails with cannot concatenate 'str' and 'NoneType' objects</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/707133" id="707133">Successful "ipa-nis-manage enable" command has exit status as 1.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/707229" id="707229">ipa-server-install with --no-host-dns still checks DNS</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/707312" id="707312">Add support for loading new zones from LDAP</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/708294" id="708294">No output while deleting a sudorule.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/709645" id="709645">Remaining external hosts not displayed while removing one from a sudorule.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/709665" id="709665">Removed external host is displayed in the output when "--all" switch is used.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710240" id="710240">Added option to Sudo rule message is displayed even when the given option already exists.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710245" id="710245">Removed option from Sudo rule message is displayed even when the given option doesn't exist.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710253" id="710253">RunAs group is not displayed in output while adding as sudorule-add-runasuser with --groups swtich.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710494" id="710494">ipa-nis-manage crashes if the specified passwd file does not exist.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710530" id="710530">ipa-nis-manage does not quit when an empty password is entered.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710592" id="710592">ipa sudocmd-add accepts blank spaces as sudo commands.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710598" id="710598">ipa sudocmdgroup-add accepts blank spaces as sudocmdgroup name.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/710601" id="710601">ipa sudorule-add accepts blank spaces as sudorule name.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/711667" id="711667">Comma separated values for --runasexternaluser option in sudorule-mod are accepted as a single value.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/711671" id="711671">Comma separated values for --runasexternalgroup option in sudorule-mod are accepted as a single value.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/711761" id="711761">Internal error while removing sudorule option without "--sudooption".</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/711786" id="711786">sudorunasgroup automatically picks up incorrect value while adding a sudorunasuser.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/712889" id="712889">Internal Error: ipa cert-remove-hold ; revocation reason 7</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713069" id="713069">Comma separated values for --externaluser option in sudorule-mod are accepted as a single value.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713374" id="713374">Misleading purpose statement for "ipa help sudorule-remove-runasuser"</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713380" id="713380">RunAs group is not displayed in output while removing as sudorule-add-runasuser with --groups swtich.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713385" id="713385">Missing label for "ipasudorunas_group".</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713481" id="713481">Removed  "RunAs External Group" is displayed in the output when "--all" switch is used.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713501" id="713501">Inconsistency in how "runas" is termed.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713531" id="713531">[ipa webui] error msg does not match with UI label</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713549" id="713549">[ipa webui] Deleting more than 2 elements leaves the Delete prompt open</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713603" id="713603">[ipa webui] inconsistent user member list</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/713798" id="713798">Set allow-recursion by default in IPA DNS</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/714238" id="714238">--sizelimit unhelpful error with *-find commands</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/714597" id="714597">ipa-client-install adds duplicate information to krb5.conf</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/714600" id="714600">ipa-client-install should configure sssd to store password if offline</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/714919" id="714919">ipa-client-install should configure hostname</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/714924" id="714924">ipa-client-install complains about non-existing nss_ldap</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/715112" id="715112">Managed Entries:  mep_mod_post_op: Unable to update mapped attributes from origin entry</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/716287" id="716287">ipa host-mod --setattr should not allow enrolledBy to be changed</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/716432" id="716432">when directory server debugging enabled, ipactl should not display debugging</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/716462" id="716462">IPA with integrated DNS - reverse zone is now being added incorrectly</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717020" id="717020">[ipa webui] When deactivating user, it updates the user, without having to click on "update" btn</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717625" id="717625">[ipa webui] Unable to update config changes</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717724" id="717724">[ipa webui] Config: Certificate Subject Base - Should not be Editable</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717726" id="717726">[ipa webui] Config: Name on the configuration page is irrelevant and means nothing to an admin</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717729" id="717729">[ipa webui] Config:  Missing configurable options</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717732" id="717732">[ipa webui] Config: Page Needs Better Organization</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/717965" id="717965">ipa config-show : should display new "Password Expiration Notification"</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/718062" id="718062">When admin resets a user's password with "ipa passwd" user's failed log in count is not reset</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/719656" id="719656">Disabling ipa-nis-manage removes netgroup compat suffix in DS.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/720011" id="720011">[ipa webui] Add Host: dns zone filter replaces text already typed in hostname.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/720013" id="720013">[ipa webui] Add Host: dns zone filter should not list reverse zones</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/720336" id="720336">WebUI not displaying admin options if the user is admin, but only via nested group</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/720711" id="720711">Users are not matched from sudo client.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/722228" id="722228">[ipa webui] Force Add Host with IP address - Allows cancel but still adds host and dns record</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/722468" id="722468">[ipa webui] Host Edit Page lists Host Name twice</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723027" id="723027">[ipa webui] Host Edit Page Missing Fields</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723233" id="723233">HBAC rule :: invalid error message now that deny rule is deprecated and help needs update</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723241" id="723241">Unexpected error message with krb Failure Count Interval on i386</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723622" id="723622">Need an arch-specific Requires on cyrus-sasl-gssapi</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723624" id="723624">Regression:  Internal Error:  Adding Host Groups</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723778" id="723778">No output while deleting an automount location.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723781" id="723781">Missing message summary while adding an automount location.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723882" id="723882">[ipa webui] Host OTP from previously added host appears in new host's edit page</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723969" id="723969">Regression: Incorrect Error message returned attempting to add user with uid 0</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/723990" id="723990">Can not create replication package with ipa-replica-prepare</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/724036" id="724036">Internal error revoking certificate - default revocation reason</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/725433" id="725433">automountmap gets added even though the return code is 1.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/725763" id="725763">Incorrect message summary while adding an automountkey.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726028" id="726028">Automountkey value doesn't get renamed.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726123" id="726123">Unable to use "--continue" option with "ipa automountkey-del".</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726454" id="726454">[ipa webui] After setting an OTP the Web UI does not indicate one was set</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726526" id="726526">Reduce number of ports used by CS in IPA by default</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726715" id="726715">Importing /etc/auto.master does not detect and import /etc/auto.direct.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726722" id="726722">Error message states 'automountlocationcn' while add/mod/del automountmap or automountkey with empty location.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726725" id="726725">Error message states 'automountmapautomountmapname' while add/mod/del automountkey with empty automountmap name.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726751" id="726751">[ipa webui] Hostgroups :: enroll :: Error 'cn' required when attempting to filter groups with hide already enrolled unchecked</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/726943" id="726943">IPA should enable configurable ports for its management web interface</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/727282" id="727282">[ipa webui] Can not get or view host certificate - Regression</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/727691" id="727691">[IPA WebUI] Identity->DNS : why there is "member" and "setting" under DNS operation</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/727921" id="727921">[ipa webui] Hostgroup :: No memberOf Net Groups Tab</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/728118" id="728118">Regression: Unknown attribute 'ipasudorunasgroup_group" displayed while adding sudo runasgroup.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/728614" id="728614">el61 - ipa-replica-install does not check for dbus, fails on certmonger</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/728950" id="728950">IPA should start even if certs are expired</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729089" id="729089">[ipa webui] Does not return appropriate error when deleting an external host but checking update dns</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729166" id="729166">ipa-server-install creates wrong reverse zone record in LDAP</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729245" id="729245">Regression: Missing message summary while adding sudooption.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729246" id="729246">Regression: Missing message summary while removing sudooption.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729377" id="729377">ipa-server-install fails on DNS errors when no DNS check is required</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/729665" id="729665">[ipa webui] Checking/Unchecking "Hide already enrolled" doesn't change list;</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/730436" id="730436">use slapi_rwlock instead of NSPR PR_RWLock directly</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/730713" id="730713">[ipa webui] Checkbox stays checked after deleting a list of objects</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/730751" id="730751">[ipa webui] inconsistency in enabling "delete" buttons</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/731784" id="731784">Add Requires on subscription-manager for entitlements</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/731804" id="731804">[IPA] When upgrading ipa from 2.0.0-23 to 2.1.0-1 uninstall is leaving leftovers and reinstall fails.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/731805" id="731805">[ipa webui] in-consistency error msg</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732084" id="732084">IPA 2.1 won't start if SELinux is disabled</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732088" id="732088">IPA man page is unclear about allowed combinations of arguments</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732468" id="732468">ipa-client-install should set LDAPSASL_NOCANON when calling ipa-getkeytab</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732521" id="732521">ipa entitle-register : prompts for rhsm password twice like you are trying to set a new password</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732803" id="732803">Rebase IPA to upstream 2.1.1</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/732996" id="732996">Access denied by HBAC rules while using the default ftp hbac service.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/733009" id="733009">ipa-client-install says system configured after an unsuccessful run</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/733436" id="733436">IPA does not always properly detect its configuration status</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/734013" id="734013">ipa-client-install breaks network configuration</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/734706" id="734706">ipa hbactest does not evaluate users from groups in an hbacrule.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/734725" id="734725">Incorrect service name in examples of ipa help hbactest.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/735187" id="735187">[ipa webui] Sudo Rule has extra User group section in "As Whom" section</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736276" id="736276">ipa hbactest fails if sourcehost is external.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736455" id="736455">[ipa webui] Sudo Rule includes indirect hosts and users members in its list to add</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736617" id="736617">ipa-client-install mishandles ntp service configuration</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736684" id="736684">ipa-client-install should sync time before kinit</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/736787" id="736787">ipa-client-install fails to join ipa server.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/737048" id="737048">ipa-client-install calls authconfig with wrong parameters</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/737516" id="737516">ipa-server files with incorrect selinux context</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/737581" id="737581">ipa host-add  Allowed to add host - hostname trailing space</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/737994" id="737994">File parameter fails if prompted for</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/737997" id="737997">should enforce some naming constraints on users and groups</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738038" id="738038">[ipa webui] Remove  Category info from HBAC and Sudo pages</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738053" id="738053">ipa-ldap-updater : Not an end user utility and the man pages should reflect this</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738339" id="738339">[ipa webui] Encode special chars in values when displaying</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/738693" id="738693">user is not prompted to enter current password when changing to a new password</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739040" id="739040">Traceback message displayed while installing ipa client on IPv6 machine.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739060" id="739060">Disable entitlement plugin and CAL counting</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739061" id="739061">Disable entitlement plugin in Web UI</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739089" id="739089">Unable to add ipa user on IPv6 machine.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739195" id="739195">[ipa webui] Unprovisioning keytab does not have cancel option</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739604" id="739604">ipa-server-install :: failing to configure CA :: restorecon returning 1 when changing context</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739640" id="739640">[ipa webui] Allowed to add service without defining service name</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/739650" id="739650">[ipa webui] IPA Server Configuration :: Issue with Default Size Limit and Default User Group</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740320" id="740320">[ipa webui] Posix checkbox for group-add has no effect</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740830" id="740830">Intermittently see "search criteria was not specific enough." while adding a hbacrule</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740838" id="740838">Missing additional info while adding a non-existing service to an hbacrule.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740844" id="740844">Missing additional info while removing a non-existing service from an hbacrule.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740850" id="740850">hbactest does not resolve canonical names during simulation.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740854" id="740854">Inconsistency in the error output while providing an invalid rule name.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740879" id="740879">[ipa webui] In adder_dialog, an object can be selected to be added multiple times.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740880" id="740880">[ipa webui] In adder_dialog, change order of >> and &lt;&lt;</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740885" id="740885">[ipa webui] In adder_dialog, no error indicated when choosing to enroll without selecting an object</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/740891" id="740891">[ipa webui] Deleting a host in HBAC Rule without selecting it, throws a browser error instead of an IPA error</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741050" id="741050">Unable to configure IPA client against IPA server with anonymous bind disabled</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741277" id="741277">[ipa webui] IN HBAC &amp; Sudo, when a category is set to 'All', entries in that category are not deleted</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741677" id="741677">ipa-client-install --password=$PASSWORD will cause /var/log/ipaclient-install.log to contain the password.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/741808" id="741808">ipa migrate-ds does not migrate all groups that are expected to migrate</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/742024" id="742024">[ipa webui] Missing option in Config tab to set default shell</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/742327" id="742327">Default DNS Administration Role  -  Permissions missing</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/742616" id="742616">IPA man pages should be more clear about the meaning of --selfsign</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/742875" id="742875">named fails to start after installing ipa server when short hostname preceeds fqdn in /etc/hosts.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743253" id="743253">duplicate hostgroup and netgroup</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743295" id="743295">[ipa webui] If adding non-posix group, unchecking posix box should disable GID field</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743788" id="743788">Title is missing while configuring browser first time</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743936" id="743936">[ipa webui] Unable to access Webui</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/743955" id="743955">Cert error when accessing host in webui or cli</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744024" id="744024">ipa-client-install return code indicates a success, even though it failed</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744074" id="744074">[ipa webui] global password policy should not be able to be deleted</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744101" id="744101">Client install fails when anonymous bind is disabled</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744234" id="744234">Internal Server Error adding invalid reverse DNS zone</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744264" id="744264">[ipa webui] missing fields in password policy page</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744306" id="744306">Unable to add Windows Synchronization Agreement</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744410" id="744410">ipa hbactest does not evaluate indirect members from groups.</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744422" id="744422">Leaks KDC password and master password via command line arguments</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/744798" id="744798">Traceback when upgrading from ipa-server-2.1.1-1 to ipa-server-2.1.2-2</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745392" id="745392">ipa-client-install hangs if the discovered server is unresponsive</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/745575" id="745575">[ipa webui] Co
