<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-12-27T11:47:03</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20111852" version="503" class="patch">
      <metadata>
        <title>RHSA-2011:1852: krb5-appl security update (Critical)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2011:1852-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1852.html"/>
      <reference source="CVE" ref_id="CVE-2011-4862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4862.html"/>
    <description>The krb5-appl packages provide Kerberos-aware telnet, ftp, rcp, rsh, and
rlogin clients and servers. Kerberos is a network authentication system
which allows clients and servers to authenticate to each other using
symmetric encryption and a trusted third-party, the Key Distribution Center
(KDC).

A buffer overflow flaw was found in the MIT krb5 telnet daemon (telnetd). A 
remote attacker who can access the telnet port of a target machine could use
this flaw to execute arbitrary code as root. (CVE-2011-4862) 

Note that the krb5 telnet daemon is not enabled by default in any version of
Red Hat Enterprise Linux. In addition, the default firewall rules block
remote access to the telnet port. This flaw does not affect the telnet
daemon distributed in the telnet-server package.

For users who have installed the krb5-appl-servers package, have enabled the 
krb5 telnet daemon, and have it accessible remotely, this update should be
applied immediately. 

All krb5-appl-server users should upgrade to these updated packages, which 
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2011-12-27"/>
        <updated date="2011-12-27"/>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2011-4862.html">CVE-2011-4862</cve>
        <bugzilla href="http://bugzilla.redhat.com/770325" id="770325">CVE-2011-4862 krb5-appl: remote buffer overflow in kerberised telnet daemon</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111852001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111852009" comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852010" comment="krb5-appl-servers is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111852007" comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852008" comment="krb5-appl-clients is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20111852005" comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20111852006" comment="krb5-appl is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_test id="oval:com.redhat.rhsa:tst:20111852001"  version="503" comment="Red Hat Enterprise Linux 6 Client is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852002"  version="503" comment="Red Hat Enterprise Linux 6 Server is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852003"  version="503" comment="Red Hat Enterprise Linux 6 Workstation is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852004"  version="503" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852005"  version="503" comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852006"  version="503" comment="krb5-appl is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852007"  version="503" comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852008"  version="503" comment="krb5-appl-clients is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852009"  version="503" comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20111852010"  version="503" comment="krb5-appl-servers is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20111852007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20111852001" />
</rpminfo_test>

  </tests>

  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_object id="oval:com.redhat.rhsa:obj:20111852002"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-client</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852001"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-server</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852007"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>krb5-appl-servers</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852006"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>krb5-appl-clients</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852003"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-workstation</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852004"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-computenode</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20111852005"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>krb5-appl</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_state id="oval:com.redhat.rhsa:ste:20111852001"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">199e2f91fd431d51</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20111852002"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version  operation="pattern match">^6[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20111852003"  version="503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">0:1.0.1-7.el6_2</evr>
</rpminfo_state>

  </states>
</oval_definitions>


