<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2012-03-22T13:27:24</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20120410" version="502" class="patch">
      <metadata>
        <title>RHSA-2012:0410: raptor security update (Important)</title>
    <affected family="unix">
      <platform>Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2012:0410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0410.html"/>
      <reference source="CVE" ref_id="CVE-2012-0037" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0037.html"/>
    <description>Raptor provides parsers for Resource Description Framework (RDF) files.

An XML External Entity expansion flaw was found in the way Raptor processed
RDF files. If an application linked against Raptor were to open a 
specially-crafted RDF file, it could possibly allow a remote attacker to 
obtain a copy of an arbitrary local file that the user running the
application had access to. A bug in the way Raptor handled external
entities could cause that application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-0037)

Red Hat would like to thank Timothy D. Morgan of VSR for reporting this
issue.

All Raptor users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against Raptor must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2012 Red Hat, Inc.</rights>
        <issued date="2012-03-22"/>
        <updated date="2012-03-22"/>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-0037.html">CVE-2012-0037</cve>
        <bugzilla href="http://bugzilla.redhat.com/791296" id="791296">CVE-2012-0037 raptor: XML External Entity (XXE) attack via RDF files</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/o:redhat:enterprise_linux</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120410001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120410002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120410003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120410004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120410005" comment="raptor is earlier than 0:1.4.18-5.el6_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120410006" comment="raptor is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120410007" comment="raptor-devel is earlier than 0:1.4.18-5.el6_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120410008" comment="raptor-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_test id="oval:com.redhat.rhsa:tst:20120410001"  version="502" comment="Red Hat Enterprise Linux 6 Client is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410002"  version="502" comment="Red Hat Enterprise Linux 6 Server is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410003"  version="502" comment="Red Hat Enterprise Linux 6 Workstation is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410004"  version="502" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410005"  version="502" comment="raptor is earlier than 0:1.4.18-5.el6_2.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410006"  version="502" comment="raptor is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410007"  version="502" comment="raptor-devel is earlier than 0:1.4.18-5.el6_2.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120410008"  version="502" comment="raptor-devel is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120410006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120410001" />
</rpminfo_test>

  </tests>

  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_object id="oval:com.redhat.rhsa:obj:20120410005"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>raptor</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120410006"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>raptor-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120410002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-client</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120410004"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-computenode</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120410003"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-workstation</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120410001"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-server</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_state id="oval:com.redhat.rhsa:ste:20120410001"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">199e2f91fd431d51</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20120410002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version  operation="pattern match">^6[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20120410003"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">0:1.4.18-5.el6_2.1</evr>
</rpminfo_state>

  </states>
</oval_definitions>

