<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2012-05-23T04:50:01</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20030315" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:315: quagga security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:315-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-315.html" />
          <reference source="CVE" ref_id="CVE-2003-0858" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0858.html" />
    
    <description>Quagga is an open source implementation of TCP/IP routing software. 
 
Herbert Xu reported that Quagga can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to
this issue. 
 
Users of Quagga should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel. 
This erratum also includes quagga-devel and quagga-contrib packages which
were not originally shipped with Red Hat Enterprise Linux 3.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0858.html">CVE-2003-0858</cve>
                <bugzilla href="http://bugzilla.redhat.com/108575" id="108575">CAN-2003-0858  Netlink local DoS: quagga</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315006" comment="quagga-devel is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315007" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315004" comment="quagga-contrib is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315005" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315002" comment="quagga is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315003" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030317" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:317: iproute security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-317.html" />
          <reference source="CVE" ref_id="CVE-2003-0856" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0856.html" />
    
    <description>The iproute package contains advanced IP routing and network device
configuration tools.

Herbert Xu reported that iproute can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0856 to
this issue. 
 
Users of iproute should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0856.html">CVE-2003-0856</cve>
                <bugzilla href="http://bugzilla.redhat.com/108573" id="108573">CAN-2003-0856 Netlink local DoS: iproute</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030317002" comment="iproute is earlier than 0:2.4.7-11.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030317003" comment="iproute is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030324" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:324: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-324.html" />
          <reference source="CVE" ref_id="CVE-2003-0925" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0925.html" />
          <reference source="CVE" ref_id="CVE-2003-0926" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0926.html" />
          <reference source="CVE" ref_id="CVE-2003-0927" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0927.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security issues affect Ethereal.  By exploiting these issues,
it may be possible to make Ethereal crash or run arbitrary code by
injecting a purposefully-malformed packet onto the wire or by convincing
someone to read a malformed packet trace file.

A buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers
to cause a denial of service and possibly execute arbitrary code via a
malformed GTP MSISDN string.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2003-0925 to
this issue.

Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of
service (crash) via certain malformed ISAKMP or MEGACO packets.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0926 to this issue.

A heap-based buffer overflow in Ethereal 0.9.15 and earlier allows
remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code via the SOCKS dissector.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0927
to this issue.

Users of Ethereal should update to these erratum packages containing
Ethereal version 0.9.16, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0925.html">CVE-2003-0925</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0926.html">CVE-2003-0926</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0927.html">CVE-2003-0927</cve>
                <bugzilla href="http://bugzilla.redhat.com/109189" id="109189">CAN-2003-0925/6/7 Ethereal 0.9.13 has three exploitable security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030324004" comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030324002" comment="ethereal is earlier than 0:0.9.16-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030334" version="501" class="patch">
      <metadata>
        <title>RHSA-2003:334: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:334-00" ref_url="https://rhn.redhat.com/errata/RHSA-2003-334.html" />
          <reference source="CVE" ref_id="CVE-2003-0859" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0859.html" />
    
    <description>The glibc packages contain GNU libc, which provides standard system libraries.

Herbert Xu reported that various applications can accept spoofed messages
sent on the kernel netlink interface by other users on the local machine.
This could lead to a local denial of service attack. The glibc function
getifaddrs uses netlink and could therefore be vulnerable to this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0859 to this issue.

In addition to the security issues, a number of other bugs were fixed.

Users are advised to upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel
and patches for the various bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-14" />
        <updated date="2003-11-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0859.html">CVE-2003-0859</cve>
                <bugzilla href="http://bugzilla.redhat.com/90402" id="90402">backtrace() is broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/101261" id="101261">getnameinfo fails to to reverse lookup on IPv6 addresses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/103727" id="103727">LD_PROFILE=libc.so.6 and sprof give seg fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/107846" id="107846">locale utility is broken on big-endian 64-bit platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108631" id="108631">LTC5138-NPTL: pthread_condtimedwait hang or mutex_lock hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108634" id="108634">Signal handler installation races with signal, glibc-2.3.2</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334012" comment="glibc-headers is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334004" comment="glibc-common is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334018" comment="nptl-devel is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334008" comment="glibc-devel is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334006" comment="glibc-debug is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334014" comment="glibc-profile is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334002" comment="glibc is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334016" comment="nscd is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334010" comment="glibc-utils is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030386" version="503" class="patch">
      <metadata>
        <title>RHSA-2003:386: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:386-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-386.html" />
          <reference source="CVE" ref_id="CVE-2003-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0967.html" />
    
    <description>FreeRADIUS is an Internet authentication daemon, which implements the
RADIUS protocol.  It allows Network Access Servers (NAS boxes) to perform
authentication for dial-up users.

The rad_decode function in FreeRADIUS 0.9.2 and earlier allows remote
attackers to cause a denial of service (crash) via a short RADIUS string
attribute with a tag, which causes memcpy to be called with a -1 length
argument, as demonstrated using the Tunnel-Password attribute.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0967 to this issue.
 
Users of FreeRADIUS are advised to upgrade to these erratum packages
containing FreeRADIUS 0.9.3 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0967.html">CVE-2003-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/110901" id="110901">CAN-2003-0967/8 FreeRadius remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386004" comment="freeradius-mysql is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386006" comment="freeradius-postgresql is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386008" comment="freeradius-unixODBC is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386002" comment="freeradius is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030395" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:395: gnupg security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-395.html" />
          <reference source="CVE" ref_id="CVE-2003-0971" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0971.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

Phong Nguyen identified a severe bug in the way GnuPG creates and uses
ElGamal keys, when those keys are used both to sign and encrypt data.  This
vulnerability can be used to trivially recover the private key.  While the
default behavior of GnuPG when generating keys does not lead to the
creation of unsafe keys, by overriding the default settings an unsafe key
could have been created.

If you are using ElGamal keys, you should revoke those keys immediately.

The packages included in this update do not make ElGamal keys safe to use;
they merely include a patch by David Shaw that disables functions that
would generate or use ElGamal keys.

To determine if your key is affected, run the following command to obtain a
list of secret keys that you have on your secret keyring:

gpg --list-secret-keys

The output of this command includes both the size and type of the keys
found, and will look similar to this example:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024D/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

The key length, type, and ID are listed together, separated by a forward
slash.  In the example output above, the key's type is "D" (DSA, sign
and encrypt).  Your key is unsafe if and only if the key type is "G"
(ElGamal, sign and encrypt).  In the above example, the secret key is safe
to use, while the secret key in the following example is not:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024G/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

For more details regarding this issue, as well as instructions on how to
revoke any keys that are unsafe, refer to the advisory available from the
GnuPG web site:

http://www.gnupg.org/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0971.html">CVE-2003-0971</cve>
                <bugzilla href="http://bugzilla.redhat.com/111345" id="111345">CAN-2003-0971 GnuPG ElGamal compromise</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395002" comment="gnupg is earlier than 0:1.2.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030399" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:399: rsync security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:399-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-399.html" />
          <reference source="CVE" ref_id="CVE-2003-0962" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0962.html" />
    
    <description>rsync is a program for sychronizing files over the network.

A heap overflow bug exists in rsync versions prior to 2.5.7.  On machines
where the rsync server has been enabled, a remote attacker could use this
flaw to execute arbitrary code as an unprivileged user.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0962 to this issue.

All users should upgrade to these erratum packages containing version
2.5.7 of rsync, which is not vulnerable to this issue.

NOTE: The rsync server is disabled (off) by default in Red Hat Enterprise
Linux.  To check if the rsync server has been enabled (on), run the
following command:

/sbin/chkconfig --list rsync

If the rsync server has been enabled but is not required, it can be
disabled by running the following command as root:

/sbin/chkconfig rsync off

Red Hat would like to thank the rsync team for their rapid response and
quick fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-04" />
        <updated date="2003-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0962.html">CVE-2003-0962</cve>
                <bugzilla href="http://bugzilla.redhat.com/111474" id="111474">CAN-2003-0962 rsync remote exploit</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399002" comment="rsync is earlier than 0:2.5.7-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030404" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:404: lftp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:404-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-404.html" />
          <reference source="CVE" ref_id="CVE-2003-0963" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0963.html" />
    
    <description>lftp is a command-line file transfer program supporting FTP and HTTP
protocols. 

Ulf Härnhammar discovered a buffer overflow bug in versions of lftp up to
and including 2.6.9.  An attacker could create a carefully crafted
directory on a website such that, if a user connects to that directory
using the lftp client and subsequently issues a 'ls' or 'rels' command, the
attacker could execute arbitrary code on the users machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0963 to this issue.

Users of lftp are advised to upgrade to these erratum packages, which
contain a backported security patch and are not vulnerable to this issue.

Red Hat would like to thank Ulf Härnhammar for discovering and alerting us
to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2003-12-16" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0963.html">CVE-2003-0963</cve>
                <bugzilla href="http://bugzilla.redhat.com/111717" id="111717">CAN-2003-0963 lftp client buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030404002" comment="lftp is earlier than 0:2.6.3-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030404003" comment="lftp is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030416" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:416: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:416-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-416.html" />
          <reference source="CVE" ref_id="CVE-2003-0985" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0985.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux
kernel versions 2.4.23 and previous which may allow a local attacker to
gain root privileges.  No exploit is currently available; however, it is
believed that this issue is exploitable (although not trivially.) The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0985 to this issue.

All users of Red Hat Enterprise Linux 3 are advised to upgrade to these
errata packages, which contain a backported security patch that corrects
this issue.

Red Hat would like to thank Paul Starzetz from ISEC for disclosing this
issue as well as Andrea Arcangeli and Solar Designer for working on the patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-07" />
        <updated date="2004-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0985.html">CVE-2003-0985</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416014" comment="kernel-source is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416002" comment="kernel is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416012" comment="kernel-doc is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416018" comment="kernel-hugemem is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416010" comment="kernel-BOOT is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416004" comment="kernel-smp-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416008" comment="kernel-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416006" comment="kernel-smp is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040002" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:002: ethereal security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-002.html" />
          <reference source="CVE" ref_id="CVE-2003-1012" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1012.html" />
          <reference source="CVE" ref_id="CVE-2003-1013" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1013.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Two security issues have been found that affect Ethereal.  By exploiting
these issues it may be possible to make Ethereal crash by injecting an
intentionally malformed packet onto the wire or by convincing someone to
read a malformed packet trace file.  It is not known if these issues could
allow arbitrary code execution.

The SMB dissector in Ethereal before 0.10.0 allows remote attackers to
cause a denial of service via a malformed SMB packet that triggers a
segmentation fault during processing of Selected packets. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-1012 to this issue.

The Q.931 dissector in Ethereal before 0.10.0 allows remote attackers to
cause a denial of service (crash) via a malformed Q.931, which triggers a
null dereference. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-1013 to this issue.

Users of Ethereal should update to these erratum packages containing
Ethereal version 0.10.0, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-05" />
        <updated date="2004-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1012.html">CVE-2003-1012</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1013.html">CVE-2003-1013</cve>
                <bugzilla href="http://bugzilla.redhat.com/112224" id="112224">CAN-2003-1012/3 Ethereal security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040002004" comment="ethereal-gnome is earlier than 0:0.10.0a-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040002002" comment="ethereal is earlier than 0:0.10.0a-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040004" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:004: cvs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-004.html" />
          <reference source="CVE" ref_id="CVE-2002-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-0844.html" />
          <reference source="CVE" ref_id="CVE-2003-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0977.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.  

A flaw was found in versions of CVS prior to 1.11.10 where a malformed
module request could cause the CVS server to attempt to create files or
directories at the root level of the file system.  However, normal file
system permissions would prevent the creation of these misplaced
directories.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0977 to this issue.

Users of CVS are advised to upgrade to these erratum packages, which
contain a patch correcting this issue.

For Red Hat Enterprise Linux 2.1, these updates also fix an off-by-one
overflow in the CVS PreservePermissions code.  The PreservePermissions 
feature is not used by default (and can only be used for local CVS). The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2002-0844 to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-14" />
        <updated date="2004-01-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-0844.html">CVE-2002-0844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0977.html">CVE-2003-0977</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004002" comment="cvs is earlier than 0:1.11.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040005" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:005: kdepim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-005.html" />
          <reference source="CVE" ref_id="CVE-2003-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0988.html" />
    
    <description>The K Desktop Environment (KDE) is a graphical desktop for the X Window
System. The KDE Personal Information Management (kdepim) suite helps you to
organize your mail, tasks, appointments, and contacts. 

The KDE team found a buffer overflow in the file information reader of
VCF files. An attacker could construct a VCF file so that when it was
opened by a victim it would execute arbitrary commands.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0988 to this issue.

Users of kdepim are advised to upgrade to these erratum packages which
contain a backported security patch that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-05" />
        <updated date="2004-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0988.html">CVE-2003-0988</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040005004" comment="kdepim-devel is earlier than 6:3.1.3-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040005005" comment="kdepim-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040005002" comment="kdepim is earlier than 6:3.1.3-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040005003" comment="kdepim is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040008" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:008: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:008-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-008.html" />
          <reference source="CVE" ref_id="CVE-2003-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0989.html" />
          <reference source="CVE" ref_id="CVE-2004-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0055.html" />
          <reference source="CVE" ref_id="CVE-2004-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0057.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic. 

George Bakos discovered flaws in the ISAKMP decoding routines of tcpdump
versions prior to 3.8.1.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0989 to this issue.

Jonathan Heusser discovered an additional flaw in the ISAKMP decoding
routines for tcpdump 3.8.1 and earlier.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0057 to
this issue.

Jonathan Heusser discovered a flaw in the print_attr_string function in the
RADIUS decoding routines for tcpdump 3.8.1 and earlier.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0055 to this issue.

Remote attackers could potentially exploit these issues by sending
carefully-crafted packets to a victim.  If the victim uses tcpdump, these
pakets could result in a denial of service, or possibly execute arbitrary
code as the 'pcap' user.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-07" />
        <updated date="2004-01-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0989.html">CVE-2003-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0055.html">CVE-2004-0055</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0057.html">CVE-2004-0057</cve>
                <bugzilla href="http://bugzilla.redhat.com/113008" id="113008">CAN-2003-0989 tcpdump parsing overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113366" id="113366">CAN-2004-0055 CAN-2004-0057 Two issues found in tpcdump</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008004" comment="libpcap is earlier than 14:0.7.2-7.E3.1" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008002" comment="tcpdump is earlier than 14:3.7.2-7.E3.1" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008003" comment="arpwatch is earlier than 14:2.1a11-7.E3.1" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040015" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:015: httpd security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:015-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-015.html" />
          <reference source="CVE" ref_id="CVE-2003-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0542.html" />
    
    <description>The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue in the handling of regular expressions from configuration files
was discovered in releases of the Apache HTTP Server version 2.0 prior to
2.0.48. To exploit this issue an attacker would need to have the ability
to write to Apache configuration files such as .htaccess or httpd.conf. A
carefully-crafted configuration file can cause an exploitable buffer
overflow and would allow the attacker to execute arbitrary code in the
context of the server (in default configurations as the 'apache' user).
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0542 to this issue.

Users of the Apache HTTP Server should upgrade to these erratum packages,
which contain backported patches correcting these issues, and are applied
to Apache version 2.0.46.  This update also includes fixes for a number of
minor bugs found in this version of the Apache HTTP Server.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-13" />
        <updated date="2004-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0542.html">CVE-2003-0542</cve>
                <bugzilla href="http://bugzilla.redhat.com/105725" id="105725">long httpd graceful reload times</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110434" id="110434">CAN-2003-0542 local buffer overflow in config file parsing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015006" comment="httpd-devel is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015004" comment="mod_ssl is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015002" comment="httpd is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040017" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:017: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 1 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-017.html" />
          <reference source="CVE" ref_id="CVE-2003-0986" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0986.html" />
          <reference source="CVE" ref_id="CVE-2004-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0001.html" />
    
    <description>The Linux kernel handles the basic functions of the operating
system.

This is the first regular kernel update for Red Hat Enterprise
Linux version 3.  It contains a new critical security fix, many
other bug fixes, several device driver updates, and numerous
performance and scalability enhancements.

On AMD64 systems, a fix was made to the eflags checking in
32-bit ptrace emulation that could have allowed local users
to elevate their privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0001 to this issue.

Other bug fixes were made in the following kernel areas:
VM, NPTL, IPC, kernel timer, ext3, NFS, netdump, SCSI,
ACPI, several device drivers, and machine-dependent
support for the x86_64, ppc64, and s390 architectures.

The VM subsystem was improved to better handle extreme
loads and resource contention (such as might occur during
heavy database application usage).  This has resulted in
a significantly reduced possibility of hangs, OOM kills,
and low-mem exhaustion.

Several NPTL fixes were made to resolve POSIX compliance
issues concerning process IDs and thread IDs.  A section
in the Release Notes elaborates on a related issue with
file record locking in multi-threaded applications.

AMD64 kernels are now configured with NUMA support,
S390 kernels now have CONFIG_BLK_STATS enabled, and
DMA capability was restored in the IA64 agpgart driver.

The following drivers have been upgraded to new versions:

  cmpci ------ 6.36
  e100 ------- 2.3.30-k1
  e1000 ------ 5.2.20-k1
  ips -------- 6.10.52
  megaraid --- v1.18k
  megaraid2 -- v2.00.9

All Red Hat Enterprise Linux 3 users are advised to upgrade
their kernels to the packages associated with their machine
architectures and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-13" />
        <updated date="2004-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0986.html">CVE-2003-0986</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0001.html">CVE-2004-0001</cve>
                <bugzilla href="http://bugzilla.redhat.com/71514" id="71514">Infinite recursion in SCSI mid layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/77839" id="77839">Assert failure in transaction.c:1224: "!jh->b_committed_data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/101938" id="101938">C write fails for records gt 2 GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102535" id="102535">hang in ptrace for gdb traceback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/104520" id="104520">SMP Kernel hang on shutdown with Intel SRCZCR Raid Controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106004" id="106004">Broadcom tg3 driver duplex won't set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106399" id="106399">SCSI I/O stall problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106502" id="106502">Base driver button not loaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106794" id="106794">LTC4829-RHEL 3 HANGS under heavy stress load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/107960" id="107960">No disk/partition statistics in /proc/partitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108488" id="108488">Millisecond timer resolution on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108648" id="108648">No AGP support on Tyan 2885 K8W</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110895" id="110895">running processes are not listed in /proc, with ps or top</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112365" id="112365">Kernel Panic when running pulse deamon</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017014" comment="kernel-source is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017002" comment="kernel is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017012" comment="kernel-doc is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017018" comment="kernel-hugemem is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017010" comment="kernel-BOOT is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017004" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017008" comment="kernel-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017006" comment="kernel-smp is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040023" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:023: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:023-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-023.html" />
          <reference source="CVE" ref_id="CVE-2003-0935" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0935.html" />
    
    <description>The Net-SNMP project includes various Simple Network Management Protocol
(SNMP) tools.

A security issue in Net-SNMP versions before 5.0.9 could allow an existing
user/community to gain access to data in MIB objects that were explicitly
excluded from their view.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0935 to this issue.

Users of Net-SNMP are advised to upgrade to these errata packages
containing Net-SNMP 5.0.9, which is not vulnerable to this issue.  In
addition, Net-SNMP 5.0.9 fixes a number of other minor bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-15" />
        <updated date="2004-01-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0935.html">CVE-2003-0935</cve>
                <bugzilla href="http://bugzilla.redhat.com/109622" id="109622">net-snmp unauthorised access to mibs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023008" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023006" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023004" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023002" comment="net-snmp is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040031" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:031: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:031-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-031.html" />
          <reference source="CVE" ref_id="CVE-2003-0924" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0924.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps), and others.

A number of temporary file bugs have been found in versions of NetPBM. 
These could make it possible for a local user to overwrite or create files
as a different user who happens to run one of the the vulnerable utilities. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0924 to this issue.

Users are advised to upgrade to the erratum packages, which contain patches
from Debian that correct these bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-19" />
        <updated date="2004-01-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0924.html">CVE-2003-0924</cve>
                <bugzilla href="http://bugzilla.redhat.com/113841" id="113841">CAN-2003-0924 netpbm temporary file vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031002" comment="netpbm is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031004" comment="netpbm-devel is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031006" comment="netpbm-progs is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040033" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:033: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-033.html" />
          <reference source="CVE" ref_id="CVE-2004-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0006.html" />
          <reference source="CVE" ref_id="CVE-2004-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0007.html" />
          <reference source="CVE" ref_id="CVE-2004-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0008.html" />
    
    <description>Gaim is an instant messenger client that can handle multiple protocols.

Stefan Esser audited the Gaim source code and found a number of bugs that
have security implications.  Due to the nature of instant messaging many of
these bugs require man-in-the-middle attacks between client and server.
However at least one of the buffer overflows could be exploited by an
attacker sending a carefully-constructed malicious message through a server.

The issues include:

Multiple buffer overflows that affect versions of Gaim 0.75 and earlier. 
1) When parsing cookies in a Yahoo web connection, 2) YMSG protocol
overflows parsing the Yahoo login webpage, 3) a YMSG packet overflow, 4)
flaws in the URL parser, and 5) flaws in HTTP Proxy connect.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0006 to these issues.

A buffer overflow in Gaim 0.74 and earlier in the Extract Info
Field Function used for MSN and YMSG protocol handlers. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0007 to this issue.

An integer overflow in Gaim 0.74 and earlier, when allocating
memory for a directIM packet results in heap overflow.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0008 to this issue.

All users of Gaim should upgrade to these erratum packages, which contain
backported security patches correcting these issues.  

Red Hat would like to thank Steffan Esser for finding and reporting these
issues and Jacques A. Vidrine for providing initial patches.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-19" />
        <updated date="2004-01-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0006.html">CVE-2004-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0007.html">CVE-2004-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0008.html">CVE-2004-0008</cve>
                <bugzilla href="http://bugzilla.redhat.com/113844" id="113844">CAN-2004-0006/7/8 Multiple vulnerabilities in Gaim</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033002" comment="gaim is earlier than 1:0.75-3.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040041" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:041: slocate security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:041-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-041.html" />
          <reference source="CVE" ref_id="CVE-2003-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0848.html" />
          <reference source="CVE" ref_id="CVE-2003-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0056.html" />
    
    <description>Slocate is a security-enhanced version of locate, designed to find files on
a system via a central database.

Patrik Hornik discovered a vulnerability in Slocate versions up to and
including 2.7 where a carefully crafted database could overflow a
heap-based buffer.  A local user could exploit this vulnerability to gain
"slocate" group privileges and then read the entire slocate database.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0848 to this issue.

Users of Slocate should upgrade to these erratum packages, which contain
Slocate version 2.7 with the addition of a patch from Kevin Lindsay that
causes slocate to drop privileges before reading a user-supplied database.

For Red Hat Enterprise Linux 2.1 these packages also fix a buffer overflow
that affected unpatched versions of Slocate prior to 2.7.  This
vulnerability could also allow a local user to gain "slocate" group
privileges.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0056 to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-21" />
        <updated date="2004-01-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0848.html">CVE-2003-0848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0056.html">CVE-2003-0056</cve>
                <bugzilla href="http://bugzilla.redhat.com/114013" id="114013">CAN-2003-0848 slocate buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114016" id="114016">CAN-2003-0056 buffer overflow in slocate</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041002" comment="slocate is earlier than 0:2.7-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040047" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:047: pwlib security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:047-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-047.html" />
          <reference source="CVE" ref_id="CVE-2004-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0097.html" />
    
    <description>PWLib is a cross-platform class library designed to support the OpenH323
project.  OpenH323 provides an implementation of the ITU H.323
teleconferencing protocol, used by packages such as Gnome Meeting.

A test suite for the H.225 protocol (part of the H.323 family) provided by
the NISCC uncovered bugs in PWLib prior to version 1.6.0.  An attacker
could trigger these bugs by sending carefully crafted messages to an
application.  The effects of such an attack can vary depending on the
application, but would usually result in a Denial of Service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0097 to this issue.

Users are advised to upgrade to the erratum packages, which contain
backported security fixes and are not vulnerable to these issues.

Red Hat would like to thank Craig Southeren of the OpenH323 project for
providing the fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-18" />
        <updated date="2004-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0097.html">CVE-2004-0097</cve>
                <bugzilla href="http://bugzilla.redhat.com/114308" id="114308">CAN-2004-0097 PWlib/OpenH323 vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040047002" comment="pwlib is earlier than 0:1.4.7-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040047003" comment="pwlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040047004" comment="pwlib-devel is earlier than 0:1.4.7-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040047005" comment="pwlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040050" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:050: mutt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:050-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-050.html" />
          <reference source="CVE" ref_id="CVE-2004-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0078.html" />
    
    <description>Mutt is a text-mode mail user agent.

A bug was found in the index menu code in versions of mutt.  A remote
attacker could send a carefully crafted mail message that can cause mutt
to segfault and possibly execute arbitrary code as the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0078 to this issue.

It is recommended that all mutt users upgrade to these updated packages,
which contain a backported security patch and are not vulnerable to this issue.

Red Hat would like to thank Niels Heinen for reporting this issue.

Note: mutt-1.2.5.1 in Red Hat Enterprise Linux 2.1 is not vulnerable to
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-11" />
        <updated date="2004-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0078.html">CVE-2004-0078</cve>
                <bugzilla href="http://bugzilla.redhat.com/114448" id="114448">CAN-2004-0078 Mutt can be remotely crashed</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050002" comment="mutt is earlier than 5:1.4.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050003" comment="mutt is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040053" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:053: sysstat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:053-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-053.html" />
          <reference source="CVE" ref_id="CVE-2004-0107" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0107.html" />
          <reference source="CVE" ref_id="CVE-2004-0108" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0108.html" />
    
    <description>Sysstat is a tool for gathering system statistics. Isag is a utility for
graphically displaying these statistics.

A bug was found in the Red Hat sysstat package post and trigger scripts,
which used insecure temporary file names. A local attacker could overwrite
system files using carefully-crafted symbolic links in the /tmp directory.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0107 to this issue.

While fixing this issue, a flaw was discovered in the isag utility, which
also used insecure temporary file names. A local attacker could overwrite
files that the user running isag has write access to using
carefully-crafted symbolic links in the /tmp directory.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0108 to this issue.

Other issues addressed in this advisory include:

* iostat -x should return all partitions on the system (up to a maximum of
1024)

* sar should handle network device names with more than 8 characters properly

* mpstat should work correctly with more than 7 CPUs as well as generate
correct statistics when accessing individual CPUs.  This issue only
affected Red Hat Enterprise Linux 2.1

* The sysstat package was not built with the proper dependencies;
therefore, it was possible that isag could not be run because the necessary
 tools were not available.  Therefore, isag was split off into its own
subpackage with the required dependencies in place.  This issue only
affects Red Hat Enterprise Linux 2.1.

Users of sysstat and isag should upgrade to these updated packages, which
contain patches to correct these issues.

NOTE: In order to use isag on Red Hat Enterprise Linux 2.1, you must
install the sysstat-isag package after upgrading.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-10" />
        <updated date="2004-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0107.html">CVE-2004-0107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0108.html">CVE-2004-0108</cve>
                <bugzilla href="http://bugzilla.redhat.com/78212" id="78212">sysstat package post scripts, trigger scripts use insecure tmp files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040053002" comment="sysstat is earlier than 0:4.0.7-4.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040053003" comment="sysstat is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040058" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:058: mod_python security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:058-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-058.html" />
          <reference source="CVE" ref_id="CVE-2003-0973" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0973.html" />
          <reference source="CVE" ref_id="CVE-2004-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0096.html" />
    
    <description>mod_python embeds the Python language interpreter within the Apache httpd
server.

A bug has been found in mod_python versions 2.7.10 and earlier that can
lead to a denial of service vulnerability.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0973 to
this issue.

Although Red Hat Enterprise Linux shipped with a version of mod_python that
contains this bug, our testing was unable to trigger the denial of service
vulnerability.  However, mod_python users are advised to upgrade to these
errata packages, which contain a backported patch that corrects this bug.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-26" />
        <updated date="2004-02-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0973.html">CVE-2003-0973</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0096.html">CVE-2004-0096</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058002" comment="mod_python is earlier than 0:3.0.3-3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040061" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:061: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:061-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-061.html" />
          <reference source="CVE" ref_id="CVE-2004-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0083.html" />
          <reference source="CVE" ref_id="CVE-2004-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0084.html" />
          <reference source="CVE" ref_id="CVE-2004-0106" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0106.html" />
    
    <description>XFree86 is an implementation of the X Window System, providing the core
graphical user interface and video drivers. 

iDefense discovered two buffer overflows in the parsing of the 'font.alias'
file.  A local attacker could exploit this vulnerability by creating a
carefully-crafted file and gaining root privileges.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0083 and CAN-2004-0084 to these issues.

Additionally David Dawes discovered additional flaws in reading font files.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0106 to these issues.

All users of XFree86 are advised to upgrade to these erratum packages,
which contain a backported fix and are not vulnerable to these issues.

Red Hat would like to thank David Dawes from XFree86 for the patches and
notification of these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-16" />
        <updated date="2004-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0083.html">CVE-2004-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0084.html">CVE-2004-0084</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0106.html">CVE-2004-0106</cve>
                <bugzilla href="http://bugzilla.redhat.com/114902" id="114902">CAN-2004-0083 XFree86 font.alias overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061052" comment="XFree86-xdm is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061022" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061036" comment="XFree86-libs-data is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061026" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061014" comment="XFree86-doc is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061010" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061002" comment="XFree86 is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061046" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061038" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061034" comment="XFree86-libs is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061054" comment="XFree86-xfs is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061006" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061056" comment="XFree86-Xnest is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061042" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061020" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061030" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061024" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061040" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061004" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061018" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061016" comment="XFree86-font-utils is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061008" comment="XFree86-base-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061058" comment="XFree86-Xvfb is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061048" comment="XFree86-twm is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061044" comment="XFree86-tools is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061050" comment="XFree86-xauth is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061012" comment="XFree86-devel is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040064" version="506" class="patch">
      <metadata>
        <title>RHSA-2004:064: samba security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:064-05" ref_url="https://rhn.redhat.com/errata/RHSA-2004-064.html" />
          <reference source="CVE" ref_id="CVE-2004-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0082.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

The Samba team discovered an issue that affects version 3.0.0 and 3.0.1 of
Samba.  If an account for a user is created, but marked as disabled using
the mksmbpasswd script, it is possible for Samba to overwrite the user's
password with the contents of an uninitialized buffer.  This might lead to
a disabled account becoming enabled with a password that could be guessed
by an attacker.

Although this is likely to be a low risk issue for most Samba users, we
have provided updated packages, which contain a backported patch correcting
this issue.

Red Hat would like to thank the Samba team for reporting this issue and
providing us with a patch.

Note: Due to a packaging error in samba-3.0.0-14.3E, the winbind daemon is
not automatically restarted when the Samba package is upgraded.  After
up2date has installed the samba-3.0.2-4.3E packages, you must run
"/sbin/service winbind condrestart" as root to restart the winbind daemon.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-21" />
        <updated date="2004-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0082.html">CVE-2004-0082</cve>
                <bugzilla href="http://bugzilla.redhat.com/114995" id="114995">CAN-2004-0082 mksmbpasswd vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064004" comment="samba-client is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064006" comment="samba-common is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064002" comment="samba is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064008" comment="samba-swat is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040066" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:066: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-066.html" />
          <reference source="CVE" ref_id="CVE-2004-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0077.html" />
    
    <description>The Linux kernel handles the basic functions of the operating
system.

Paul Starzetz discovered a flaw in return value checking in mremap() in the
Linux kernel versions 2.4.24 and previous that may allow a local attacker
to gain root privileges.  No exploit is currently available; however this
issue is exploitable. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0077 to this issue.

All users are advised to upgrade to these errata packages, which contain
backported security patches that correct these issues.   

Red Hat would like to thank Paul Starzetz from ISEC for reporting this issue.

For the IBM S/390 and IBM eServer zSeries architectures, the upstream
version of the s390utils package (which fixes a bug in the zipl
bootloader) is also included.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-20" />
        <updated date="2004-02-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0077.html">CVE-2004-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/112891" id="112891">OOM killer strikes with lots of free swap space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113517" id="113517">RHEL 3.0 smp hang using prctl( PR_SET_PDEATHSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115820" id="115820">CAN-2004-0077 Linux kernel do_mremap VMA limit local privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066014" comment="kernel-source is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066002" comment="kernel is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066012" comment="kernel-doc is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066016" comment="kernel-hugemem is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066010" comment="kernel-BOOT is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066008" comment="kernel-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066004" comment="kernel-smp is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066020" comment="s390utils is earlier than 2:1.2.4-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040066021" comment="s390utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040072" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:072: nfs-utils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:072-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-072.html" />
          <reference source="CVE" ref_id="CVE-2004-0154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0154.html" />
    
    <description>The nfs-utils package contains the rpc.mountd program, which implements the
NFS mount protocol.

A flaw was discovered in versions of rpc.mountd in nfs-utils versions after
1.0.3 and prior to 1.0.6.  When mounting a directory, rpc.mountd could
crash if the reverse lookup of the client in DNS failed to match the
forward lookup.  An attacker who has the ability to mount remote
directories from a server could make use of this flaw to cause a denial of
service by making rpc.mountd crash.

Users are advised to upgrade to these updated packages, which contain
nfs-utils 1.0.6 and is not vulnerable to this issue.

NOTE: Red Hat Enterprise Linux 2.1 includes a version of rpc.mountd that is
not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-11" />
        <updated date="2004-03-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0154.html">CVE-2004-0154</cve>
                <bugzilla href="http://bugzilla.redhat.com/114535" id="114535">rpc.mountd killed by remote mount request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072002" comment="nfs-utils is earlier than 0:1.0.6-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072003" comment="nfs-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040084" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:084: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:084-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-084.html" />
          <reference source="CVE" ref_id="CVE-2004-0113" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0113.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

A memory leak in mod_ssl in the Apache HTTP Server prior to version 2.0.49
allows a remote denial of service attack against an SSL-enabled server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0113 to this issue.

This update also includes various bug fixes, including:

- Improvements to the mod_expires, mod_dav, mod_ssl, and mod_proxy modules

- A fix for a bug causing core dumps during configuration parsing on the
IA64 platform

- An updated version of mod_include fixing several edge cases in the SSI parser

Additionally, the mod_logio module is now included.

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-23" />
        <updated date="2004-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0113.html">CVE-2004-0113</cve>
                <bugzilla href="http://bugzilla.redhat.com/112771" id="112771">Invalid paths in config_vars.mk crash build of mod_jk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113929" id="113929">mod_expires headers not set when used in conjunction with mod_proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113934" id="113934">SRPMS: test for MMN version it too fragile</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115328" id="115328">Satisfy keyword in httpd.conf causes apache to segfault on load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115379" id="115379">pcre conflict between httpd and php</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117280" id="117280">CAN-2004-0113 mod_ssl Denial of Service attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084004" comment="httpd-devel is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084006" comment="mod_ssl is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084002" comment="httpd is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040090" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:090: libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-090.html" />
          <reference source="CVE" ref_id="CVE-2004-0110" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0110.html" />
    
    <description>libxml2 is a library for manipulating XML files.

Yuuichi Teranishi discovered a flaw in libxml2 versions prior to 2.6.6. 
When fetching a remote resource via FTP or HTTP, libxml2 uses special
parsing routines.  These routines can overflow a buffer if passed a very
long URL.  If an attacker is able to find an application using libxml2 that
parses remote resources and allows them to influence the URL, then this
flaw could be used to execute arbitrary code.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0110
to this issue.

All users are advised to upgrade to these updated packages, which contain a
backported fix and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-26" />
        <updated date="2004-02-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0110.html">CVE-2004-0110</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090002" comment="libxml2 is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090003" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090004" comment="libxml2-devel is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090005" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090006" comment="libxml2-python is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090007" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040103" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:103: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-103.html" />
          <reference source="CVE" ref_id="CVE-2004-0111" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0111.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the 
GNOME GUI desktop environment.  

Thomas Kristensen discovered a bitmap file that would cause versions of
gdk-pixbuf prior to 0.20 to crash.  To exploit this flaw, an attacker would
need to get a victim to open a carefully-crafted BMP file in an application
that used gdk-pixbuf.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0111 to this issue.

Users are advised to upgrade to these updated packages containing
gdk-pixbuf version 0.22, which is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-10" />
        <updated date="2004-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0111.html">CVE-2004-0111</cve>
                <bugzilla href="http://bugzilla.redhat.com/116918" id="116918">CAN-2004-0111 gdk-pixbuf can crash with malicious BMP file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103002" comment="gdk-pixbuf is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040110" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:110: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:110-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-110.html" />
          <reference source="CVE" ref_id="CVE-2003-0564" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0564.html" />
          <reference source="CVE" ref_id="CVE-2003-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0594.html" />
          <reference source="CVE" ref_id="CVE-2004-0191" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0191.html" />
    
    <description>Mozilla is a Web browser and mail reader, designed for standards
compliance, performance and portability.  Network Security Services (NSS)
is a set of libraries designed to support cross-platform development of
security-enabled server applications. 

NISCC testing of implementations of the S/MIME protocol uncovered a number
of bugs in NSS versions prior to 3.9.   The parsing of unexpected ASN.1
constructs within S/MIME data could cause Mozilla to crash or consume large
amounts of memory.  A remote attacker could potentially trigger these bugs
by sending a carefully-crafted S/MIME message to a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0564 to this issue. 

Andreas Sandblad discovered a cross-site scripting issue that affects
various versions of Mozilla.  When linking to a new page it is still
possible to interact with the old page before the new page has been
successfully loaded. Any Javascript events will be invoked in the context
of the new page, making cross-site scripting possible if the different
pages belong to different domains.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0191 to
this issue. 

Flaws have been found in the cookie path handling between a number of Web
browsers and servers. The HTTP cookie standard allows a Web server
supplying a cookie to a client to specify a subset of URLs on the origin
server to which the cookie applies. Web servers such as Apache do not
filter returned cookies and assume that the client will only send back
cookies for requests that fall within the server-supplied subset of URLs.
However, by supplying URLs that use path traversal (/../) and character
encoding, it is possible to fool many browsers into sending a cookie to a
path outside of the originally-specified subset.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0594 to this issue. 

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.4.2 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-02" />
        <updated date="2004-04-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0564.html">CVE-2003-0564</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0594.html">CVE-2003-0594</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0191.html">CVE-2004-0191</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110018" comment="mozilla-js-debugger is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110014" comment="mozilla-mail is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110016" comment="mozilla-chat is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110010" comment="mozilla-nss-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110002" comment="mozilla is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110020" comment="mozilla-dom-inspector is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110006" comment="mozilla-nspr-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110004" comment="mozilla-nspr is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110012" comment="mozilla-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110008" comment="mozilla-nss is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040120" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:120: openssl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:120-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-120.html" />
          <reference source="CVE" ref_id="CVE-2004-0079" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0079.html" />
          <reference source="CVE" ref_id="CVE-2004-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0081.html" />
          <reference source="CVE" ref_id="CVE-2004-0112" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0112.html" />
    
    <description>The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),
Transport Layer Security (TLS v1) protocols, and serves as a full-strength
general purpose cryptography library.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a null-pointer assignment in the do_change_cipher_spec() function
in OpenSSL 0.9.6c-0.9.6k and 0.9.7a-0.9.7c.  A remote attacker could
perform a carefully crafted SSL/TLS handshake against a server that uses
the OpenSSL library in such a way as to cause OpenSSL to crash. Depending
on the application this could lead to a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0079 to this issue.

Stephen Henson discovered a flaw in SSL/TLS handshaking code when using
Kerberos ciphersuites in OpenSSL 0.9.7a-0.9.7c.  A remote attacker could
perform a carefully crafted SSL/TLS handshake against a server configured
to use Kerberos ciphersuites in such a way as to cause OpenSSL to crash. 
Most applications have no ability to use Kerberos ciphersuites and will
therefore be unaffected by this issue.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0112 to
this issue.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a bug in older versions of OpenSSL 0.9.6 prior to 0.9.6d that may
lead to a denial of service attack (infinite loop).  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0081 to this issue.  This issue affects only the OpenSSL
compatibility packages shipped with Red Hat Enterprise Linux 3.

These updated packages contain patches provided by the OpenSSL group that
protect against these issues.

Additionally, the version of libica included in the OpenSSL packages has
been updated to 1.3.5. This only affects IBM s390 and IBM eServer zSeries
customers and is required for the latest openCryptoki packages.

NOTE: Because server applications are affected by this issue, users are
advised to either restart all services that use OpenSSL functionality or
restart their systems after installing these updates.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-21" />
        <updated date="2004-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0079.html">CVE-2004-0079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0081.html">CVE-2004-0081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0112.html">CVE-2004-0112</cve>
                <bugzilla href="http://bugzilla.redhat.com/117770" id="117770">CAN-2004-0079/0081/0112 Flaws in OpenSSL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120002" comment="openssl is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120006" comment="openssl-perl is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120004" comment="openssl-devel is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120008" comment="openssl096b is earlier than 0:0.9.6b-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040133" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:133: squid security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:133-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-133.html" />
          <reference source="CVE" ref_id="CVE-2004-0189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0189.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A bug was found in the processing of %-encoded characters in a URL in
versions of Squid 2.5.STABLE4 and earlier.  If a Squid configuration uses
Access Control Lists (ACLs), a remote attacker could create URLs that would
not be correctly tested against Squid's ACLs, potentially allowing clients
to access prohibited URLs.

Users of Squid should update to these erratum packages which are not
vulnerable to this issue.

In addition, these packages contain a new Access Control type, "urllogin",
which can be used to protect vulnerable Microsoft Internet Explorer clients
from accessing URLs that contain login information.  Such URLs are often
used by fraudsters to trick web users into revealing valuable personal data.

Note that the default Squid configuration does not make use of this new
access control type.  You must explicitly configure Squid with ACLs that
use this new type, in accordance with your own site policies.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0189.html">CVE-2004-0189</cve>
                <bugzilla href="http://bugzilla.redhat.com/118032" id="118032">CAN-2004-0189 Squid ACL bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133002" comment="squid is earlier than 7:2.5.STABLE3-5.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040136" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:136: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-136.html" />
          <reference source="CVE" ref_id="CVE-2004-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0176.html" />
          <reference source="CVE" ref_id="CVE-2004-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0365.html" />
          <reference source="CVE" ref_id="CVE-2004-0367" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0367.html" />
          <reference source="CVE" ref_id="CVE-2004-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1761.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Stefan Esser reported that Ethereal versions 0.10.1 and earlier contain
stack overflows in the IGRP, PGM, Metflow, ISUP, TCAP, or IGAP dissectors.
 On a system where Ethereal is being run a remote attacker could send
malicious packets that could cause Ethereal to crash or execute arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0176 to this issue.

Jonathan Heussser discovered that a carefully-crafted RADIUS packet could
cause a crash.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0365 to this issue.

Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of
service (crash) via a zero-length Presentation protocol selector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0367 to this issue.

Users of Ethereal should upgrade to these updated packages, which contain
a version of Ethereal that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-30" />
        <updated date="2004-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0176.html">CVE-2004-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0365.html">CVE-2004-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0367.html">CVE-2004-0367</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1761.html">CVE-2004-1761</cve>
                <bugzilla href="http://bugzilla.redhat.com/118143" id="118143">CAN-2004-0176 Ethereal  dissector overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040136004" comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040136002" comment="ethereal is earlier than 0:0.10.3-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040153" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:153: cvs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:153-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-153.html" />
          <reference source="CVE" ref_id="CVE-2004-0180" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0180.html" />
          <reference source="CVE" ref_id="CVE-2004-0405" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0405.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.  

Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can
create files with absolute pathnames.  An attacker could create a fake
malicious CVS server that would cause arbitrary files to be created or
overwritten when a victim connects to it.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0180 to
this issue.

Derek Price discovered a vulnerability whereby a CVS pserver could be
abused by a malicious client to view the contents of certain files outside
of the CVS root directory using relative pathnames containing "../". The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0405 to this issue.

Users of CVS are advised to upgrade to these erratum packages, which
contain a patch correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0180.html">CVE-2004-0180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0405.html">CVE-2004-0405</cve>
                <bugzilla href="http://bugzilla.redhat.com/118719" id="118719">CAN-2004-0180 Malicious CVS server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040153002" comment="cvs is earlier than 0:1.11.2-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040160" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:160: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-160.html" />
          <reference source="CVE" ref_id="CVE-2004-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0179.html" />
    
    <description>OpenOffice.org is an Open Source, community-developed, multi-platform
office productivity suite.  OpenOffice internally uses inbuilt code
from neon, an HTTP and WebDAV client library.

Versions of the neon client library up to and including 0.24.4 have been
found to contain a number of format string bugs.  An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using OpenOffice.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0179 to this issue.

Users of OpenOffice are advised to upgrade to these updated packages, which
contain a patch correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0179.html">CVE-2004-0179</cve>
                <bugzilla href="http://bugzilla.redhat.com/119830" id="119830">CAN-2004-0179 neon format string vulnerability affects openoffice</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160006" comment="openoffice.org-i18n is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160002" comment="openoffice.org is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160004" comment="openoffice.org-libs is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040165" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:165: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-165.html" />
          <reference source="CVE" ref_id="CVE-2004-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0155.html" />
          <reference source="CVE" ref_id="CVE-2004-0164" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0164.html" />
          <reference source="CVE" ref_id="CVE-2004-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0403.html" />
    
    <description>IPSEC uses strong cryptography to provide both authentication and
encryption services.

With versions of ipsec-tools prior to 0.2.3, it was possible for an
attacker to cause unauthorized deletion of SA (Security Associations.)
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0164 to this issue.

With versions of ipsec-tools prior to 0.2.5, the RSA signature on x.509
certificates was not properly verified when using certificate based
authentication.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0155 to this issue.

When ipsec-tools receives an ISAKMP header, it will attempt to allocate
sufficient memory for the entire ISAKMP message according to the header's
length field. If an attacker crafts an ISAKMP header with a extremely large
value in the length field, racoon may exceed operating system resource
limits and be terminated, resulting in a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0403 to this issue.

User of IPSEC should upgrade to this updated package, which contains
ipsec-tools version 0.25 along with a security patch for CAN-2004-0403
which resolves all these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-11" />
        <updated date="2004-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0155.html">CVE-2004-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0164.html">CVE-2004-0164</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0403.html">CVE-2004-0403</cve>
                <bugzilla href="http://bugzilla.redhat.com/120253" id="120253">CAN-2004-0155/CAN-2004-0164/CAN-2004-0403 IPSEC vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165002" comment="ipsec-tools is earlier than 0:0.2.5-0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040174" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:174: utempter security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:174-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-174.html" />
          <reference source="CVE" ref_id="CVE-2004-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0233.html" />
    
    <description>Utempter is a utility that allows terminal applications such as xterm and
screen to update utmp and wtmp without requiring root privileges.

Steve Grubb discovered a flaw in Utempter which allowed device names
containing directory traversal sequences such as '/../'.  In combination
with an application that trusts the utmp or wtmp files, this could allow a
local attacker the ability to overwrite privileged files using a symlink.

Users should upgrade to this new version of utempter, which fixes this
vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0233.html">CVE-2004-0233</cve>
                <bugzilla href="http://bugzilla.redhat.com/121332" id="121332">CAN-2004-0233 utempter directory traversal symlink attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040174002" comment="utempter is earlier than 0:0.5.5-1.3EL.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040174003" comment="utempter is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040178" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:178: lha security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:178-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-178.html" />
          <reference source="CVE" ref_id="CVE-2004-0234" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0234.html" />
          <reference source="CVE" ref_id="CVE-2004-0235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0235.html" />
    
    <description>LHA is an archiving and compression utility for LHarc format archives.

Ulf Harnhammar discovered two stack buffer overflows and two directory
traversal flaws in LHA.  An attacker could exploit the buffer overflows by
creating a carefully crafted LHA archive in such a way that arbitrary code
would be executed when the archive is tested or extracted by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0234 to this issue.  An attacker could exploit
the directory traversal issues to create files as the victim outside of the
expected directory.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0235 to this issue.

Users of LHA should update to this updated package which contains
backported patches not vulnerable to these issues.

Red Hat would like to thank Ulf Harnhammar for disclosing and providing
test cases and patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0234.html">CVE-2004-0234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0235.html">CVE-2004-0235</cve>
                <bugzilla href="http://bugzilla.redhat.com/121417" id="121417">CAN-2004-0234/0235 lha security flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178002" comment="lha is earlier than 0:1.14i-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178003" comment="lha is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040180" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:180: libpng security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-180.html" />
          <reference source="CVE" ref_id="CVE-2004-0421" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0421.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.  

Steve Grubb discovered a out of bounds memory access flaw in libpng.  An
attacker could carefully craft a PNG file in such a way that it would cause
an application linked to libpng to crash when opened by a victim.  This
issue may not be used to execute arbitrary code.  

Users are advised to upgrade to these updated packages that contain a
backported security fix not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0421.html">CVE-2004-0421</cve>
                <bugzilla href="http://bugzilla.redhat.com/121229" id="121229">CAN-2004-0421 libpng can access out of bounds memory</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180002" comment="libpng is earlier than 2:1.2.2-21" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180004" comment="libpng-devel is earlier than 2:1.2.2-21" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180008" comment="libpng10-devel is earlier than 0:1.0.13-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180006" comment="libpng10 is earlier than 0:1.0.13-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040183" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:183: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:183-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-183.html" />
          <reference source="CVE" ref_id="CVE-2004-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0109.html" />
          <reference source="CVE" ref_id="CVE-2004-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0424.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

iSEC Security Research discovered a flaw in the ip_setsockopt() function
code of the Linux kernel versions 2.4.22 to 2.4.25 inclusive.  This flaw 
also affects the 2.4.21 kernel in Red Hat Enterprise Linux 3 which
contained a backported version of the affected code.  A local user could
use this flaw to gain root privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0424 to
this issue.

iDefense reported a buffer overflow flaw in the ISO9660 filesystem code.
An attacker could create a malicious filesystem in such a way that root
privileges may be obtained if the filesystem is mounted. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0109 to this issue.

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-22" />
        <updated date="2004-04-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0109.html">CVE-2004-0109</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0424.html">CVE-2004-0424</cve>
                <bugzilla href="http://bugzilla.redhat.com/120028" id="120028">CAN-2004-0109 kernel iso9660 buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121314" id="121314">CAN-2004-0424 Linux kernel setsockopt MCAST_MSFILTER integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183006" comment="kernel-source is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183002" comment="kernel is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183008" comment="kernel-doc is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183018" comment="kernel-hugemem is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183010" comment="kernel-BOOT is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183004" comment="kernel-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183014" comment="kernel-smp is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040188" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:188: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 2 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:188-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-188.html" />
          <reference source="CVE" ref_id="CVE-2003-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0461.html" />
          <reference source="CVE" ref_id="CVE-2003-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0465.html" />
          <reference source="CVE" ref_id="CVE-2003-0984" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0984.html" />
          <reference source="CVE" ref_id="CVE-2003-1040" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1040.html" />
          <reference source="CVE" ref_id="CVE-2004-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0003.html" />
          <reference source="CVE" ref_id="CVE-2004-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0010.html" />
    
    <description>The Linux kernel handles the basic functions of the
operating system.

This is the second regular kernel update to Red Hat
Enterprise Linux version 3.  It contains several minor
security fixes, many bug fixes, device driver updates,
new hardware support, and the introduction of Linux
Syscall Auditing support.

There were bug fixes in many different parts of the kernel,
the bulk of which addressed unusual situations such as error
handling, race conditions, and resource starvation.  The
combined effect of the approximately 140 fixes is a strong
improvement in the reliability and durability of Red Hat
Enterprise Linux.  Some of the key areas affected are disk
drivers, network drivers, USB support, x86_64 and ppc64
platform support, ia64 32-bit emulation layer enablers,
and the VM, NFS, IPv6, and SCSI subsystems.

A significant change in the SCSI subsystem (the disabling
of the scsi-affine-queue patch) should significantly improve
SCSI disk driver performance in many scenarios.  There were
10 Bugzillas against SCSI performance problems addressed
by this change.

The following drivers have been upgraded to new versions:

  bonding ---- 2.4.1
  cciss ------ 2.4.50.RH1
  e1000 ------ 5.2.30.1-k1
  fusion ----- 2.05.11.03
  ipr -------- 1.0.3
  ips -------- 6.11.07
  megaraid2 -- 2.10.1.1
  qla2x00 ---- 6.07.02-RH1
  tg3 -------- 3.1
  z90crypt --- 1.1.4

This update introduces support for the new Intel EM64T
processor.  A new "ia32e" architecture has been created to
support booting on platforms based on either the original
AMD Opteron CPU or the new Intel EM64T CPU.  The existing
"x86_64" architecture has remained optimized for Opteron
systems.  Kernels for both types of systems are built from
the same x86_64-architecture sources and share a common
kernel source RPM (kernel-source-2.4.21-15.EL.x86_64.rpm).

Other highlights in this update include a major upgrade to
the SATA infrastructure, addition of IBM JS20 Power Blade
support, and creation of an optional IBM eServer zSeries
On-Demand Timer facility for reducing idle CPU overhead.

The following security issues were addressed in this update:

A minor flaw was found where /proc/tty/driver/serial reveals
the exact character counts for serial links.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0461 to this issue.

The kernel strncpy() function in Linux 2.4 and 2.5 does not
pad the target buffer with null bytes on architectures other
than x86, as opposed to the expected libc behavior, which
could lead to information leaks.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0465 to this issue.

A minor data leak was found in two real time clock drivers
(for /dev/rtc).  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name
CAN-2003-0984 to this issue.

A flaw in the R128 Direct Render Infrastructure (dri) driver
could allow local privilege escalation.  This driver is part
of the kernel-unsupported package.  The Common Vulnera-
bilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0003 to this issue.

A flaw in ncp_lookup() in ncpfs could allow local privilege
escalation.  The ncpfs module allows a system to mount
volumes of NetWare servers or print to NetWare printers and
is in the kernel-unsupported package.  The Common Vulnera-
bilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0010 to this issue.

(Note that the kernel-unsupported package contains drivers
and other modules that are unsupported and therefore might
contain security problems that have not been addressed.)

All Red Hat Enterprise Linux 3 users are advised to upgrade
their kernels to the packages associated with their machine
architectures and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-11" />
        <updated date="2004-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0461.html">CVE-2003-0461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0465.html">CVE-2003-0465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0984.html">CVE-2003-0984</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1040.html">CVE-2003-1040</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0003.html">CVE-2004-0003</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0010.html">CVE-2004-0010</cve>
                <bugzilla href="http://bugzilla.redhat.com/102194" id="102194">Disk READ performance worse compared with 2.4.20-18.9smp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/104633" id="104633">The synchronous write() system call of RHEL3.0 is slower than that of RHEL2.1.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106503" id="106503">ia64 kernel stops allocating memory too early when overcommit_memory set to strict</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106584" id="106584">'cp -p' returns error when destination is an nfs directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106969" id="106969">Random stall during boot-up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108958" id="108958">MINSIGSTKSZ mismatch between ia32 and ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109618" id="109618">3ware raid extremely low throughput</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109843" id="109843">Typo in module parameter  of scsi_mod module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109914" id="109914">PATCH: LTC5351-Large external array causes SIGILL in 32-bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110170" id="110170">[PATCH] LTC5381- rhel 3 will need to pick up the cyclone-lpj-fix patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110999" id="110999">clock is running to fast on IBM x445</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111250" id="111250">tg3 driver fails to autonegotiate correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111264" id="111264">ada compiler crashes on even hello-world</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111287" id="111287">[PATCH] alternate signal stack bug corrupts RNaT bits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111629" id="111629">ACL over NFS problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111681" id="111681">Invalid ICMP type 11 messages echo'd to console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111768" id="111768">/proc/pid/statm can return negative values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111903" id="111903">[PATCH] oops in IUCV code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111911" id="111911">avoid hang during initialization on I/O errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112190" id="112190">Duplicate get_partition_list bug to track Bugzilla 111342 in Taroon -</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112359" id="112359">RHEL 3.0 using v6.06.00b11 driver attached to McData switch doesn't log in or scan devices successfully.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112449" id="112449">(TG3) driver doesn't work properly with bcm5700 nic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112584" id="112584">reservation error code, corrupts request queue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112764" id="112764">RHEL3 kernel not preventing or recovering from fork bomb when ulimit used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112826" id="112826">LTC5732 - MMIO alignment error when inserting the olympic TR module.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113071" id="113071">[PATCH] RHEL3 ia64: 32 bit applications don't dump core properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113072" id="113072">[PATCH] RHEL3/ia64: strace -f on multithreaded 32 bit applications doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113099" id="113099">CAN-2003-0461 /proc reveals char count</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113100" id="113100">CAN-2003-0465 kernel strncpy padding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113103" id="113103">CAN-2003-0984 minor /dev/rtc leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113171" id="113171">lousy read performance on megaraid with 2.4.21-4.0.2.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113341" id="113341">netdump - various race conditions that lead to hangs in panic()/die()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113413" id="113413">too many ipv6 aliases cause kernel oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113604" id="113604">CAN-2004-0003 r128 DRI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113809" id="113809">depmod is not run for kernel-2.4.21-9.EL from Quaterly Update #1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113890" id="113890">[PATCH] Excutable compiled on x86 can cause kernel seg fault on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114052" id="114052">Raw device performance poor under WS 3 Dreamworks IT#29689</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114135" id="114135">LSI Megaraid(2) performance subpar in RHEL3, using RHEL3 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114553" id="114553">Bad performance with Q1 update kernel (-9EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114560" id="114560">zfcp updates for RHEL3 U2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114773" id="114773">Panic in elf_core_copy_regs() core dumping ia32 binary</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114869" id="114869">date returns future year of 586562</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114940" id="114940">RHEL 3.0 default QLogic driver v6.06.00b11 spews sg_low_free and QUEUE FULL messages at load time.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114942" id="114942">Running I/O on RHEL 3.0 and using the v6.06.00b11 driver, the driver ran out of memory and began arbitrarily killing processes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115273" id="115273">bad disk I/O performance with the 2.4.21-4.ELsmp kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115438" id="115438">strange load - kswapd/IO ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115823" id="115823">CAN-2004-0010 ncpfs hole (unsupported)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116916" id="116916">tg3 driver doesn't support bonding driver's ALB mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117741" id="117741">P4 2.8ghz HT, Using RHEL WS 3.0 Update 1, latest SMP Kernel, see only 1 CPU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117941" id="117941">frequent kernel panics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118397" id="118397">system needlessly thrashing swap partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118556" id="118556">MTRRs not initialized correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118647" id="118647">kswapd in state R and D load constant at 1+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118882" id="118882">Machine doesn't boot SMP Kernel after installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118885" id="118885">[PATCH] kernel panics when removing expired IPsec SAs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119174" id="119174">/proc/cpuinfo vendor_id is wrong. shows $</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119545" id="119545">kernel module binfmt_misc missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119903" id="119903">nfs peformance very bad on EL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120341" id="120341">Runaway processes with USB console on Blade Center</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122077" id="122077">servers freeze (only respond to ping and sysrq) periodically</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188006" comment="kernel-source is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188002" comment="kernel is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188008" comment="kernel-doc is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188014" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188016" comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188018" comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188004" comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188012" comment="kernel-smp is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040190" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:190: cvs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:190-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-190.html" />
          <reference source="CVE" ref_id="CVE-2004-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0396.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.

Stefan Esser discovered a flaw in cvs where malformed "Entry"
lines could cause a heap overflow.  An attacker who has access to a CVS
server could use this flaw to execute arbitrary code under the UID which
the CVS server is executing.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0396 to this issue.

Users of CVS are advised to upgrade to this updated package, which contains
a backported patch correcting this issue.

Red Hat would like to thank Stefan Esser for notifying us of this issue and
Derek Price for providing an updated patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0396.html">CVE-2004-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/122384" id="122384">CAN-2004-0396 CVS pserver heap overflow via Entry/Is-modified/Unchanged</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040190002" comment="cvs is earlier than 0:1.11.2-22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040192" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:192: rsync security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:192-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-192.html" />
          <reference source="CVE" ref_id="CVE-2004-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0426.html" />
    
    <description>Rsync is a program for synchronizing files over a network.

Rsync before 2.6.1 does not properly sanitize paths when running a
read/write daemon without using chroot.  This could allow a remote attacker
to write files outside of the module's "path", depending on the privileges
assigned to the rsync daemon.  Users not running an rsync daemon, running a
read-only daemon, or running a chrooted daemon are not affected by this
issue.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0426 to this issue.

Users of Rsync are advised to upgrade to this updated package, which
contains a backported patch and is not affected by this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0426.html">CVE-2004-0426</cve>
                <bugzilla href="http://bugzilla.redhat.com/122511" id="122511">CAN-2004-0426 rsync directory traversal</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040192002" comment="rsync is earlier than 0:2.5.7-4.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040219" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:219: tcpdump security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-219.html" />
          <reference source="CVE" ref_id="CVE-2004-0183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0183.html" />
          <reference source="CVE" ref_id="CVE-2004-0184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0184.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic. 

Tcpdump v3.8.1 and earlier versions contained multiple flaws in the
packet display functions for the ISAKMP protocol.  Upon receiving
specially crafted ISAKMP packets, TCPDUMP would try to read beyond
the end of the packet capture buffer and subsequently crash.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0183.html">CVE-2004-0183</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0184.html">CVE-2004-0184</cve>
                <bugzilla href="http://bugzilla.redhat.com/120022" id="120022">CAN-2004-0183/0184 tcpdump ISAKMP crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123030" id="123030">CAN-2004-0183/0184 tcpdump ISAKMP crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219004" comment="libpcap is earlier than 14:0.7.2-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219002" comment="tcpdump is earlier than 14:3.7.2-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219006" comment="arpwatch is earlier than 14:2.1a11-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040233" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:233: cvs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:233-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-233.html" />
          <reference source="CVE" ref_id="CVE-2004-0414" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0414.html" />
          <reference source="CVE" ref_id="CVE-2004-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0416.html" />
          <reference source="CVE" ref_id="CVE-2004-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0417.html" />
          <reference source="CVE" ref_id="CVE-2004-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0418.html" />
          <reference source="CVE" ref_id="CVE-2004-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0778.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.

While investigating a previously fixed vulnerability, Derek Price
discovered a flaw relating to malformed "Entry" lines which lead to a
missing NULL terminator.   The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0414 to this issue.

Stefan Esser and Sebastian Krahmer conducted an audit of CVS and fixed a
number of issues that may have had security consequences.

Among the issues deemed likely to be exploitable were: 

-- a double-free relating to the error_prog_name string (CAN-2004-0416)
-- an argument integer overflow (CAN-2004-0417)
-- out-of-bounds writes in serv_notify (CAN-2004-0418).

An attacker who has access to a CVS server may be able to execute arbitrary
code under the UID on which the CVS server is executing. 

Users of CVS are advised to upgrade to this updated package, which contains
backported patches correcting these issues.

Red Hat would like to thank Stefan Esser, Sebastian Krahmer, and Derek
Price for auditing, disclosing, and providing patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0414.html">CVE-2004-0414</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0416.html">CVE-2004-0416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0417.html">CVE-2004-0417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0418.html">CVE-2004-0418</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0778.html">CVE-2004-0778</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040233002" comment="cvs is earlier than 0:1.11.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040234" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:234: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:234-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-234.html" />
          <reference source="CVE" ref_id="CVE-2004-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0504.html" />
          <reference source="CVE" ref_id="CVE-2004-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0505.html" />
          <reference source="CVE" ref_id="CVE-2004-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0506.html" />
          <reference source="CVE" ref_id="CVE-2004-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0507.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

The MMSE dissector in Ethereal releases 0.10.1 through 0.10.3 contained a
buffer overflow flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0507 to this issue.

In addition, other flaws in Ethereal prior to 0.10.4 were found that could
cause it to crash in response to carefully crafted SIP (CAN-2004-0504), AIM
(CAN-2004-0505), or SPNEGO (CAN-2004-0506) packets.

Users of Ethereal should upgrade to these updated packages, which contain
backported security patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0504.html">CVE-2004-0504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0505.html">CVE-2004-0505</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0506.html">CVE-2004-0506</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0507.html">CVE-2004-0507</cve>
                <bugzilla href="http://bugzilla.redhat.com/124534" id="124534">CAN-2004-0504/5/6/7 Ethereal 0.10.4 contains security fixes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040234004" comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040234002" comment="ethereal is earlier than 0:0.10.3-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040236" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:236: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:236-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-236.html" />
          <reference source="CVE" ref_id="CVE-2004-0523" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0523.html" />
    
    <description>Kerberos is a network authentication system.

Bugs have been fixed in the krb5_aname_to_localname library function.
Specifically, buffer overflows were possible for all Kerberos versions up
to and including 1.3.3. The krb5_aname_to_localname function translates a
Kerberos principal name to a local account name, typically a UNIX username.
This function is frequently used when performing authorization checks.

If configured with mappings from particular Kerberos principals to
particular UNIX user names, certain functions called by
krb5_aname_to_localname will not properly check the lengths of buffers
used to store portions of the principal name.  If configured to map
principals to user names using rules, krb5_aname_to_localname would
consistently write one byte past the end of a buffer allocated from the
heap.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0523 to this issue.

Only configurations which enable the explicit mapping or rules-based
mapping functionality of krb5_aname_to_localname() are vulnerable.
These configurations are not the default.

Users of Kerberos are advised to upgrade to these erratum packages which
contain backported security patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0523.html">CVE-2004-0523</cve>
                <bugzilla href="http://bugzilla.redhat.com/125001" id="125001">CAN-2004-0523 MIT Kerberos 5: buffer overflows in krb5_aname_to_localname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236006" comment="krb5-libs is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236004" comment="krb5-devel is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236008" comment="krb5-server is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236002" comment="krb5 is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236010" comment="krb5-workstation is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040240" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:240: squirrelmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:240-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-240.html" />
          <reference source="CVE" ref_id="CVE-2004-0519" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0519.html" />
          <reference source="CVE" ref_id="CVE-2004-0520" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0520.html" />
          <reference source="CVE" ref_id="CVE-2004-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0521.html" />
    
    <description>SquirrelMail is a webmail package written in PHP.  Multiple
vulnerabilities have been found which affect the version of SquirrelMail
shipped with Red Hat Enterprise Linux 3.

An SQL injection flaw was found in SquirrelMail version 1.4.2 and earlier.
If SquirrelMail is configured to store user addressbooks in the database, a
remote attacker could use this flaw to execute arbitrary SQL statements.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0521 to this issue.

A number of cross-site scripting (XSS) flaws in SquirrelMail version 1.4.2
and earlier could allow remote attackers to execute script as other web
users.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-0519 and CAN-2004-0520 to these issues.

All users of SquirrelMail are advised to upgrade to the erratum package
containing SquirrelMail version 1.4.3a which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-14" />
        <updated date="2004-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0519.html">CVE-2004-0519</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0520.html">CVE-2004-0520</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0521.html">CVE-2004-0521</cve>
                <bugzilla href="http://bugzilla.redhat.com/122512" id="122512">CAN-2004-0519/20/21 XSS and SQL issues in Squirrelmail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240002" comment="squirrelmail is earlier than 0:1.4.3-0.e3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040242" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:242: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:242-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-242.html" />
          <reference source="CVE" ref_id="CVE-2004-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0541.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow was found within the NTLM authentication helper
routine.  If Squid is configured to use the NTLM authentication helper, 
a remote attacker could potentially execute arbitrary code by sending a
lengthy password.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0541 to this issue.

Note: The NTLM authentication helper is not enabled by default in Red Hat
Enterprise Linux 3.  Red Hat Enterprise Linux 2.1 is not vulnerable to this
issue as it shipped with a version of Squid which did not contain the helper.  

Users of Squid should update to this errata package which contains a
backported patch that is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0541.html">CVE-2004-0541</cve>
                <bugzilla href="http://bugzilla.redhat.com/125507" id="125507">CAN-2004-0541 Squid NTLM authentication helper overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040242002" comment="squid is earlier than 7:2.5.STABLE3-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040249" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:249: libpng security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:249-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-249.html" />
          <reference source="CVE" ref_id="CVE-2002-1363" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-1363.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.  

During an audit of Red Hat Linux updates, the Fedora Legacy team found a
security issue in libpng that had not been fixed in Red Hat Enterprise
Linux 3.  An attacker could carefully craft a PNG file in such a way that
it would cause an application linked to libpng to crash or potentially
execute arbitrary code when opened by a victim.  

Note: this issue does not affect Red Hat Enterprise Linux 2.1

Users are advised to upgrade to these updated packages that contain a
backported security fix and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-18" />
        <updated date="2004-06-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-1363.html">CVE-2002-1363</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249002" comment="libpng is earlier than 2:1.2.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249004" comment="libpng-devel is earlier than 2:1.2.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249008" comment="libpng10-devel is earlier than 0:1.0.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249006" comment="libpng10 is earlier than 0:1.0.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040255" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:255: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:255-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-255.html" />
          <reference source="CVE" ref_id="CVE-2004-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0427.html" />
          <reference source="CVE" ref_id="CVE-2004-0495" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0495.html" />
          <reference source="CVE" ref_id="CVE-2004-0554" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0554.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw was found in Linux kernel versions 2.4 and 2.6 for x86 and x86_64
that allowed local users to cause a denial of service (system crash) by
triggering a signal handler with a certain sequence of fsave and frstor
instructions.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0554 to this issue.

Another flaw was discovered in an error path supporting the clone()
system call that allowed local users to cause a denial of service
(memory leak) by passing invalid arguments to clone() running in an
infinite loop of a user's program.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0427
to this issue.

Enhancements were committed to the 2.6 kernel by Al Viro which enabled the
Sparse source code checking tool to check for a certain class of kernel
bugs. A subset of these fixes also applies to various drivers in the 2.4
kernel.  Although the majority of these resides in drivers unsupported in
Red Hat Enterprise Linux 3, the flaws could lead to privilege escalation or
access to kernel memory.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0495 to these issues.

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.  These packages contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-17" />
        <updated date="2004-06-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0427.html">CVE-2004-0427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0495.html">CVE-2004-0495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0554.html">CVE-2004-0554</cve>
                <bugzilla href="http://bugzilla.redhat.com/125794" id="125794">CAN-2004-0554 local user can get the kernel to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125901" id="125901">[PATCH] CAN-2004-0554: FPU exception handling local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125968" id="125968">last RH kernel affected bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126121" id="126121">CAN-2004-0495 Sparse security fixes backported for 2.4 kernel</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255004" comment="kernel-source is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255002" comment="kernel is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255006" comment="kernel-doc is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255016" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255018" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255014" comment="kernel-smp is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040259" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:259: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:259-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-259.html" />
          <reference source="CVE" ref_id="CVE-2004-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0600.html" />
          <reference source="CVE" ref_id="CVE-2004-0686" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0686.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.  
  
Evgeny Demidov discovered a flaw in the internal routine used by the Samba
Web Administration Tool (SWAT) in Samba versions 3.0.2 through 3.0.4.  When
decoding base-64 data during HTTP basic authentication, an invalid base-64
character could cause a buffer overflow.  If the SWAT administration
service is enabled, this flaw could allow an attacker to execute arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0600 to this issue.

Additionally, the Samba team discovered a buffer overflow in the code used
to support the 'mangling method = hash' smb.conf option.  Please be aware
that the default setting for this parameter is 'mangling method = hash2'
and therefore not vulnerable.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0686 to this issue.

This release includes the updated upstream version 3.0.4 together with 
backported security patches to correct these issues as well as a number of
post-3.0.4 bug fixes from the Samba subversion repository.  
 
The most important bug fix allows Samba users to change their passwords 
if Microsoft patch KB 828741 (a critical update) had been applied. 
 
All users of Samba should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-22" />
        <updated date="2004-07-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0600.html">CVE-2004-0600</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0686.html">CVE-2004-0686</cve>
                <bugzilla href="http://bugzilla.redhat.com/102715" id="102715">samba spec needs epoch in versioned dependecies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114436" id="114436">samba consumes all memory then hangs z390 vmachine.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116560" id="116560">Missing BuildRequires: krb5-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117181" id="117181">local variable used before set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119211" id="119211">smb.conf(5) manual page bug if you do not use  UTF-8 based locale</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121356" id="121356">spec file should install libsmbclient.so with executable permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122527" id="122527">Need 'printing = cups' and 'cups options = raw'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122749" id="122749">Samba is unable to read international characters in filenames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123271" id="123271">Users get error message when changing passwords after applying KB828741</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125714" id="125714">NTBackup cannot access samba shares</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126296" id="126296">Requesting updated packages to 3.0.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127909" id="127909">CAN-2004-0600 Buffer Overrun in memcpy()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128227" id="128227">CAN-2004-0686 buffer overflow in 'mangling method = hash' code.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259004" comment="samba-client is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259006" comment="samba-common is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259002" comment="samba is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259008" comment="samba-swat is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040308" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:308: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-308.html" />
          <reference source="CVE" ref_id="CVE-2004-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0607.html" />
    
    <description>IPSEC uses strong cryptography to provide both authentication and
encryption services.

When configured to use X.509 certificates to authenticate remote hosts,
ipsec-tools versions 0.3.3 and earlier will attempt to verify that host
certificate, but will not abort the key exchange if verification fails.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0607 to this issue.

Users of ipsec-tools should upgrade to this updated package which contains
a backported security patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-29" />
        <updated date="2004-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0607.html">CVE-2004-0607</cve>
                <bugzilla href="http://bugzilla.redhat.com/126568" id="126568">CAN-2004-0607 racoon authentication bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040308002" comment="ipsec-tools is earlier than 0:0.2.5-0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040323" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:323: lha security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-323.html" />
          <reference source="CVE" ref_id="CVE-2004-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0769.html" />
          <reference source="CVE" ref_id="CVE-2004-0771" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0771.html" />
          <reference source="CVE" ref_id="CVE-2004-0694" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0694.html" />
          <reference source="CVE" ref_id="CVE-2004-0745" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0745.html" />
    
    <description>LHA is an archiving and compression utility for LHarc format archives.

Lukasz Wojtow discovered a stack-based buffer overflow in all versions
of lha up to and including version 1.14.  A carefully created archive could
allow an attacker to execute arbitrary code when a victim extracts or tests
the archive.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0769 to this issue.

Buffer overflows were discovered in the command line processing of all
versions of lha up to and including version 1.14.  If a malicious user
could trick a victim into passing a specially crafted command line to the
lha command, it is possible that arbitrary code could be executed.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-0771 and CAN-2004-0694 to these issues.

Thomas Biege discovered a shell meta character command execution
vulnerability in all versions of lha up to and including 1.14.  An attacker
could create a directory with shell meta characters in its name which could
lead to arbitrary command execution.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0745 to
this issue.

Users of lha should update to this updated package which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0769.html">CVE-2004-0769</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0771.html">CVE-2004-0771</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0694.html">CVE-2004-0694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0745.html">CVE-2004-0745</cve>
                <bugzilla href="http://bugzilla.redhat.com/126740" id="126740">CAN-2004-0694 Buffer overflow in lha (CAN-2004-0745, CAN-2004-0769, CAN-2004-0771)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040323002" comment="lha is earlier than 0:1.14i-10.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178003" comment="lha is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040342" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:342: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:342-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-342.html" />
          <reference source="CVE" ref_id="CVE-2004-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0488.html" />
          <reference source="CVE" ref_id="CVE-2004-0493" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0493.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

A stack buffer overflow was discovered in mod_ssl that could be triggered
if using the FakeBasicAuth option. If mod_ssl was sent a client certificate
with a subject DN field longer than 6000 characters, a stack overflow
occured if FakeBasicAuth had been enabled. In order to exploit this issue
the carefully crafted malicious certificate would have had to be signed by
a Certificate Authority which mod_ssl is configured to trust. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0488 to this issue.

A remotely triggered memory leak in the Apache HTTP Server earlier than
version 2.0.50 was also discovered.  This allowed a remote attacker to
perform a denial of service attack against the server by forcing it to
consume large amounts of memory.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0493 to this issue.

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-06" />
        <updated date="2004-07-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0488.html">CVE-2004-0488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0493.html">CVE-2004-0493</cve>
                <bugzilla href="http://bugzilla.redhat.com/125046" id="125046">CAN-2004-0488 mod_ssl ssl_util_uuencode_binary() stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126863" id="126863">CAN-2004-0493 folding header DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342004" comment="httpd-devel is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342006" comment="mod_ssl is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342002" comment="httpd is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040349" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:349: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-349.html" />
          <reference source="CVE" ref_id="CVE-2004-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0748.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

An input filter bug in mod_ssl was discovered in Apache httpd version
2.0.50 and earlier.  A remote attacker could force an SSL connection to be
aborted in a particular state and cause an Apache child process to enter an
infinite loop, consuming CPU resources.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0748 to
this issue.

Additionally, this update includes the following enhancements and bug fixes:

- included an improved version of the mod_cgi module that correctly handles    
  concurrent output on stderr and stdout

- included support for direct lookup of SSL variables using %{SSL:...}
  from mod_rewrite, or using %{...}s from mod_headers

- restored support for use of SHA1-encoded passwords

- added the mod_ext_filter module

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0748.html">CVE-2004-0748</cve>
                <bugzilla href="http://bugzilla.redhat.com/112216" id="112216">4097+ bytes of stderr from cgi script causes script to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117959" id="117959">Apache autoindex corrupt when > 2GB file in tree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119651" id="119651">HTTP authentication against password file with SHA1 password hashes fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120072" id="120072">please enable mod_ext_filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120096" id="120096">mod_ssl environment variables not available in mod_rewrite rules</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349004" comment="httpd-devel is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349006" comment="mod_ssl is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349002" comment="httpd is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040350" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:350: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-350.html" />
          <reference source="CVE" ref_id="CVE-2004-0642" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0642.html" />
          <reference source="CVE" ref_id="CVE-2004-0643" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0643.html" />
          <reference source="CVE" ref_id="CVE-2004-0644" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0644.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

Several double-free bugs were found in the Kerberos 5 KDC and libraries.  A
remote attacker could potentially exploit these flaws to execuate arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0642 and CAN-2004-0643 to these issues.

A double-free bug was also found in the krb524 server (CAN-2004-0772),
however this issue does not affect Red Hat Enterprise Linux 3 Kerberos
packages.

An infinite loop bug was found in the Kerberos 5 ASN.1 decoder library.  A
remote attacker may be able to trigger this flaw and cause a denial of
service. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0644 to this issue.

When attempting to contact a KDC, the Kerberos libraries will iterate
through the list of configured servers, attempting to contact each in turn.
If one of the servers becomes unresponsive, the client will time out and
contact the next configured server.  When the library attempts to contact
the next KDC, the entire process is repeated.  For applications which must
contact a KDC several times, the accumulated time spent waiting can become
significant.

This update modifies the libraries, notes which server for a given realm
last responded to a request, and attempts to contact that server first
before contacting any of the other configured servers.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-31" />
        <updated date="2004-08-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0642.html">CVE-2004-0642</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0643.html">CVE-2004-0643</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0644.html">CVE-2004-0644</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350006" comment="krb5-libs is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350004" comment="krb5-devel is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350008" comment="krb5-server is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350002" comment="krb5 is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350010" comment="krb5-workstation is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040360" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:360: kernel security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:360-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-360.html" />
          <reference source="CVE" ref_id="CVE-2004-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0497.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

During an audit of the Linux kernel, SUSE discovered a flaw that allowed
a user to make unauthorized changes to the group ID of files in certain
circumstances. In the 2.4 kernel, as shipped with Red Hat Enterprise
Linux, the only way this could happen is through the kernel nfs server. A
user on a system that mounted a remote file system from a vulnerable
machine may be able to make unauthorized changes to the group ID of
exported files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0497 to this issue.

Only Red Hat Enterprise Linux systems that are configured to share
file systems via NFS are affected by this issue.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-02" />
        <updated date="2004-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0497.html">CVE-2004-0497</cve>
                <bugzilla href="http://bugzilla.redhat.com/126716" id="126716">CAN-2004-0497 inode_change_ok missing checks allows GID changes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360004" comment="kernel-source is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360002" comment="kernel is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360006" comment="kernel-doc is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360018" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360014" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360012" comment="kernel-smp is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040373" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:373: gnome-vfs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-373.html" />
          <reference source="CVE" ref_id="CVE-2004-0494" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0494.html" />
    
    <description>GNOME VFS is the GNOME virtual file system. It provides a modular
architecture and ships with several modules that implement support for file
systems, HTTP, FTP, and others.  The extfs backends make it possible to
implement file systems for GNOME VFS using scripts.

Flaws have been found in several of the GNOME VFS extfs backend scripts. 
Red Hat Enterprise Linux ships with vulnerable scripts, but they are not
used by default.  An attacker who is able to influence a user to open a
specially-crafted URI using gnome-vfs could perform actions as that user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0494 to this issue.

Users of Red Hat Enterprise Linux should upgrade to these updated packages,
which remove these unused scripts.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0494.html">CVE-2004-0494</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040373004" comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040373005" comment="gnome-vfs2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040373002" comment="gnome-vfs2 is earlier than 0:2.2.5-2E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040373003" comment="gnome-vfs2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040378" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:378: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:378-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-378.html" />
          <reference source="CVE" ref_id="CVE-2004-0633" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0633.html" />
          <reference source="CVE" ref_id="CVE-2004-0634" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0634.html" />
          <reference source="CVE" ref_id="CVE-2004-0635" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0635.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

The SNMP dissector in Ethereal releases 0.8.15 through 0.10.4 contained a
memory read flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
possibly execute arbitrary code.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0635 to this issue.

The SMB dissector in Ethereal releases 0.9.15 through 0.10.4 contained a
null  pointer flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0634 to this issue.

The iSNS dissector in Ethereal releases 0.10.3 through 0.10.4 contained an
integer overflow flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
possibly execute arbitrary code.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0633 to this issue.

Users of Ethereal should upgrade to these updated packages, which contain
a version that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-28" />
        <updated date="2004-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0633.html">CVE-2004-0633</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0634.html">CVE-2004-0634</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0635.html">CVE-2004-0635</cve>
                <bugzilla href="http://bugzilla.redhat.com/127381" id="127381">CAN-2004-0633/34/35 Multiple problems in Ethereal 0.10.4</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040378004" comment="ethereal-gnome is earlier than 0:0.10.5-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040378002" comment="ethereal is earlier than 0:0.10.5-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040392" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:392: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-392.html" />
          <reference source="CVE" ref_id="CVE-2004-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0594.html" />
          <reference source="CVE" ref_id="CVE-2004-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0595.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP server.

Stefan Esser discovered a flaw when memory_limit is enabled in versions of
PHP 4 before 4.3.8. If a remote attacker could force the PHP interpreter to
allocate more memory than the memory_limit setting before script execution
begins, then the attacker may be able to supply the contents of a PHP hash
table remotely. This hash table could then be used to execute arbitrary
code as the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0594 to this issue.

This issue has a higher risk when PHP is running on an instance of Apache
which is vulnerable to CAN-2004-0493.  For Red Hat Enterprise Linux 3, this
Apache memory exhaustion issue was fixed by a previous update,
RHSA-2004:342.  It may also be possible to exploit this issue if using a
non-default PHP configuration with the "register_defaults" setting is
changed to "On". Red Hat does not believe that this flaw is exploitable in
the default configuration of Red Hat Enterprise Linux 3.

Stefan Esser discovered a flaw in the strip_tags function in versions of
PHP before 4.3.8.  The strip_tags function is commonly used by PHP scripts
to prevent Cross-Site-Scripting attacks by removing HTML tags from
user-supplied form data.  By embedding NUL bytes into form data, HTML tags
can in some cases be passed intact through the strip_tags function, which
may allow a Cross-Site-Scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0595 to
this issue.  

All users of PHP are advised to upgrade to these updated packages, which
contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-19" />
        <updated date="2004-07-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0594.html">CVE-2004-0594</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0595.html">CVE-2004-0595</cve>
                <bugzilla href="http://bugzilla.redhat.com/127642" id="127642">CAN-2004-0594 PHP memory_limit issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392014" comment="php-odbc is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392010" comment="php-mysql is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392002" comment="php is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392012" comment="php-pgsql is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392004" comment="php-devel is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392006" comment="php-imap is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392008" comment="php-ldap is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040400" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:400: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:400-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-400.html" />
          <reference source="CVE" ref_id="CVE-2004-0500" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0500.html" />
          <reference source="CVE" ref_id="CVE-2004-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0754.html" />
          <reference source="CVE" ref_id="CVE-2004-0784" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0784.html" />
          <reference source="CVE" ref_id="CVE-2004-0785" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0785.html" />
    
    <description>Gaim is an instant messenger client that can handle multiple protocols.

Buffer overflow bugs were found in the Gaim MSN protocol handler.  In order
to exploit these bugs, an attacker would have to perform a man in the
middle attack between the MSN server and the vulnerable Gaim client.  Such
an attack could allow arbitrary code execution.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0500
to this issue.

Buffer overflow bugs have been found in the Gaim URL decoder, local
hostname resolver, and the RTF message parser.  It is possible that a
remote attacker could send carefully crafted data to a vulnerable client
and lead to a crash or arbitrary code execution.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0785 to this issue.

A shell escape bug has been found in the Gaim smiley theme file
installation.  When a user installs a smiley theme, which is contained
within a tar file, the unarchiving of the data is done in an unsafe manner.
An attacker could create a malicious smiley theme that would execute
arbitrary commands if the theme was installed by the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0784 to this issue.

An integer overflow bug has been found in the Gaim Groupware message
receiver.  It is possible that if a user connects to a malicious server,
an attacker could send carefully crafted data which could lead to arbitrary
code execution on the victims machine.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0754 to
this issue.

Users of Gaim are advised to upgrade to this updated package which
contains Gaim version 0.82 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-07" />
        <updated date="2004-09-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0500.html">CVE-2004-0500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0754.html">CVE-2004-0754</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0784.html">CVE-2004-0784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0785.html">CVE-2004-0785</cve>
                <bugzilla href="http://bugzilla.redhat.com/126842" id="126842">CAN-2004-0500 Gaim MSN protocol vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040400002" comment="gaim is earlier than 1:0.82.1-0.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040402" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:402: libpng security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-402.html" />
          <reference source="CVE" ref_id="CVE-2002-1363" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-1363.html" />
          <reference source="CVE" ref_id="CVE-2004-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0597.html" />
          <reference source="CVE" ref_id="CVE-2004-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0598.html" />
          <reference source="CVE" ref_id="CVE-2004-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0599.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

During a source code audit, Chris Evans discovered several buffer overflows
in libpng.  An attacker could create a carefully crafted PNG file in such a
way that it would cause an application linked with libpng to execute
arbitrary code when the file was opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0597 to these issues.  

In addition, this audit discovered a potential NULL pointer dereference in
libpng (CAN-2004-0598) and several integer overflow issues (CAN-2004-0599).
An attacker could create a carefully crafted PNG file in such a way that
it would cause an application linked with libpng to crash when the file was
opened by the victim.

Red Hat would like to thank Chris Evans for discovering these issues.

For users of Red Hat Enterprise Linux 2.1 these patches also include a more
complete fix for the out of bounds memory access flaw (CAN-2002-1363). 

All users are advised to update to the updated libpng packages which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-1363.html">CVE-2002-1363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0597.html">CVE-2004-0597</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0598.html">CVE-2004-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0599.html">CVE-2004-0599</cve>
                <bugzilla href="http://bugzilla.redhat.com/127869" id="127869">CAN-2004-0597/98/99 multiple problems in libpng 1.2.5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402004" comment="libpng10-devel is earlier than 0:1.0.13-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402002" comment="libpng10 is earlier than 0:1.0.13-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402006" comment="libpng is earlier than 2:1.2.2-25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402008" comment="libpng-devel is earlier than 2:1.2.2-25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040409" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:409: sox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-409.html" />
          <reference source="CVE" ref_id="CVE-2004-0557" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0557.html" />
    
    <description>SoX (Sound eXchange) is a sound file format converter. SoX can convert
between many different digitized sound formats and perform simple sound
manipulation functions, including sound effects.

Buffer overflows existed in the parsing of WAV file header fields. It was
possible that a malicious WAV file could have caused arbitrary code to be
executed when the file was played or converted.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0557
to these issues.

All users of sox should upgrade to these updated packages, which resolve
these issues as well as fix a number of minor bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-29" />
        <updated date="2004-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0557.html">CVE-2004-0557</cve>
                <bugzilla href="http://bugzilla.redhat.com/79151" id="79151">largefile support missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/91144" id="91144">SoX's soxplay doesn't except paths containg spaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102499" id="102499">sox RPM does not install soxmix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127502" id="127502">-r option dumps core on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128158" id="128158">CAN-2004-0557 buffer overflows in sox</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040409004" comment="sox-devel is earlier than 0:12.17.4-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040409005" comment="sox-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040409002" comment="sox is earlier than 0:12.17.4-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040409003" comment="sox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040412" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:412: kdelibs, kdebase security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:412-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-412.html" />
          <reference source="CVE" ref_id="CVE-2004-0689" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0689.html" />
          <reference source="CVE" ref_id="CVE-2004-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0746.html" />
          <reference source="CVE" ref_id="CVE-2004-0721" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0721.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment.
The kdebase packages include core applications for the K Desktop Environment.

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create
temporary directories with predictable names.  A local attacker could
prevent KDE applications from functioning correctly, or overwrite files
owned by other users by creating malicious symlinks.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-0689
to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web
browser Konqueror allows websites to set cookies for certain country
specific secondary top level domains.  An attacker within one of the
affected domains could construct a cookie which would be sent to all other
websites within the domain leading to a session fixation attack.  This
issue does not affect popular domains such as .co.uk, .co.in, or .com.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the
Konqueror web browser.  This issue could allow a malicious website to show
arbitrary content in a named frame of a different browser window.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0746 to this issue.

All users of KDE are advised to upgrade to these erratum packages,
which contain backported patches from the KDE team for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-05" />
        <updated date="2004-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0689.html">CVE-2004-0689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0746.html">CVE-2004-0746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0721.html">CVE-2004-0721</cve>
                <bugzilla href="http://bugzilla.redhat.com/128462" id="128462">CAN-2004-0721 Konqueror frame injection spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128693" id="128693">CAN-2004-0689 Predictable temporary filenames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129228" id="129228">CAN-2004-0746 Konqueror Cross-Domain Cookie Injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412002" comment="kdebase is earlier than 6:3.1.3-5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412004" comment="kdebase-devel is earlier than 6:3.1.3-5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412006" comment="kdelibs is earlier than 6:3.1.3-6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412008" comment="kdelibs-devel is earlier than 6:3.1.3-6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040413" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:413: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-413.html" />
          <reference source="CVE" ref_id="CVE-2004-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0178.html" />
          <reference source="CVE" ref_id="CVE-2004-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0415.html" />
          <reference source="CVE" ref_id="CVE-2004-0447" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0447.html" />
          <reference source="CVE" ref_id="CVE-2004-0535" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0535.html" />
          <reference source="CVE" ref_id="CVE-2004-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0587.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered flaws in the Linux kernel when handling file
offset pointers.  These consist of invalid conversions of 64 to 32-bit file
offset pointers and possible race conditions.  A local unprivileged user
could make use of these flaws to access large portions of kernel memory. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0415 to this issue.  

These packages contain a patch written by Al Viro to correct these flaws. 
Red Hat would like to thank iSEC Security Research for disclosing this
issue and a number of vendor-sec participants for reviewing and working on
the patch to this issue.

In addition, these packages correct a number of minor security issues:

An bug in the e1000 network driver.  This bug could be used by local users
to leak small amounts of kernel memory (CAN-2004-0535).

A bug in the SoundBlaster 16 code which does not properly handle certain
sample sizes.  This flaw could be used by local users to crash a system 
(CAN-2004-0178).

A possible NULL-pointer dereference in the Linux kernel prior to 2.4.26 on
the Itanium platform could allow a local user to crash a system
(CAN-2004-0447).

Inappropriate permissions on /proc/scsi/qla2300/HbaApiNode (CAN-2004-0587).

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-03" />
        <updated date="2004-08-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0178.html">CVE-2004-0178</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0415.html">CVE-2004-0415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0447.html">CVE-2004-0447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0535.html">CVE-2004-0535</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0587.html">CVE-2004-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/120527" id="120527">CAN-2004-0447 [PATCH] IPF kernel crashes under gdb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121045" id="121045">CAN-2004-0178 Soundblaster 16 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125168" id="125168">CAN-2004-0535 e1000 kernel memory information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126396" id="126396">CAN-2004-0587 Bad permissions on qla* drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126402" id="126402">CAN-2004-0447 NULL-pointer dereference in unwind.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126414" id="126414">CAN-2004-0415 file offset pointer signedness issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413004" comment="kernel-source is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413002" comment="kernel is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413006" comment="kernel-doc is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413016" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413018" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413014" comment="kernel-smp is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040414" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:414: qt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:414-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-414.html" />
          <reference source="CVE" ref_id="CVE-2004-0691" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0691.html" />
          <reference source="CVE" ref_id="CVE-2004-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0692.html" />
          <reference source="CVE" ref_id="CVE-2004-0693" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0693.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3.   An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-20" />
        <updated date="2004-08-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0691.html">CVE-2004-0691</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0692.html">CVE-2004-0692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0693.html">CVE-2004-0693</cve>
                <bugzilla href="http://bugzilla.redhat.com/128720" id="128720">CAN-2004-0691 BMP decoder heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129502" id="129502">CAN-2004-0692 XPM decoder integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414008" comment="qt-ODBC is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414009" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414014" comment="qt-designer is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414015" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414002" comment="qt is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414003" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414004" comment="qt-config is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414005" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414010" comment="qt-MySQL is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414011" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414006" comment="qt-devel is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414007" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414012" comment="qt-PostgreSQL is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414013" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040421" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:421: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-421.html" />
          <reference source="CVE" ref_id="CVE-2004-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0597.html" />
          <reference source="CVE" ref_id="CVE-2004-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0599.html" />
          <reference source="CVE" ref_id="CVE-2004-0718" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0718.html" />
          <reference source="CVE" ref_id="CVE-2004-0722" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0722.html" />
          <reference source="CVE" ref_id="CVE-2004-0757" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0757.html" />
          <reference source="CVE" ref_id="CVE-2004-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0758.html" />
          <reference source="CVE" ref_id="CVE-2004-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0759.html" />
          <reference source="CVE" ref_id="CVE-2004-0760" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0760.html" />
          <reference source="CVE" ref_id="CVE-2004-0761" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0761.html" />
          <reference source="CVE" ref_id="CVE-2004-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0762.html" />
          <reference source="CVE" ref_id="CVE-2004-0763" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0763.html" />
          <reference source="CVE" ref_id="CVE-2004-0764" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0764.html" />
          <reference source="CVE" ref_id="CVE-2004-0765" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0765.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A number of flaws have been found in Mozilla 1.4 that have been fixed in
the Mozilla 1.4.3 release: 

Zen Parse reported improper input validation to the SOAPParameter object
constructor leading to an integer overflow and controllable heap
corruption.  Malicious JavaScript could be written to utilize this flaw and
could allow arbitrary code execution.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0722 to
this issue.

During a source code audit, Chris Evans discovered a buffer overflow and
integer overflows which affect the libpng code inside Mozilla. An attacker
could create a carefully crafted PNG file in such a way that it would cause
Mozilla to crash or execute arbitrary code when the image was viewed.
(CAN-2004-0597, CAN-2004-0599)

Zen Parse reported a flaw in the POP3 capability.  A malicious POP3 server
could send a carefully crafted response that would cause a heap overflow
and potentially allow execution of arbitrary code as the user running
Mozilla. (CAN-2004-0757)

Marcel Boesch found a flaw that allows a CA certificate to be imported with
a DN the same as that of the built-in CA root certificates, which can cause
a denial of service to SSL pages, as the malicious certificate is treated
as invalid. (CAN-2004-0758)

Met - Martin Hassman reported a flaw in Mozilla that could allow malicious
Javascript code to upload local files from a users machine without
requiring confirmation. (CAN-2004-0759)

Mindlock Security reported a flaw in ftp URI handling.  By using a NULL
character (%00) in a ftp URI, Mozilla can be confused into opening a
resource as a different MIME type. (CAN-2004-0760)

Mozilla does not properly prevent a frame in one domain from injecting
content into a frame that belongs to another domain, which facilitates
website spoofing and other attacks, also known as the frame injection
vulnerability.  (CAN-2004-0718)

Tolga Tarhan reported a flaw that can allow a malicious webpage to use a
redirect sequence to spoof the security lock icon that makes a webpage
appear to be encrypted.  (CAN-2004-0761)

Jesse Ruderman reported a security issue that affects a number of browsers
including Mozilla that could allow malicious websites to install arbitrary
extensions by using interactive events to manipulate the XPInstall Security
dialog box. (CAN-2004-0762)

Emmanouel Kellinis discovered a caching flaw in Mozilla which allows
malicious websites to spoof certificates of trusted websites via
redirects and Javascript that uses the "onunload" method. (CAN-2004-0763)

Mozilla allowed malicious websites to hijack the user interface via the
"chrome" flag and XML User Interface Language (XUL) files. (CAN-2004-0764)

The cert_TestHostName function in Mozilla only checks the hostname portion
of a certificate when the hostname portion of the URI is not a fully
qualified domain name (FQDN).  This flaw could be used for spoofing if an
attacker had control of machines on a default DNS search path. (CAN-2004-0765)

All users are advised to update to these erratum packages which contain a
snapshot of Mozilla 1.4.3 including backported fixes and are not vulnerable
to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0597.html">CVE-2004-0597</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0599.html">CVE-2004-0599</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0718.html">CVE-2004-0718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0722.html">CVE-2004-0722</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0757.html">CVE-2004-0757</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0758.html">CVE-2004-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0759.html">CVE-2004-0759</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0760.html">CVE-2004-0760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0761.html">CVE-2004-0761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0762.html">CVE-2004-0762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0763.html">CVE-2004-0763</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0764.html">CVE-2004-0764</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0765.html">CVE-2004-0765</cve>
                <bugzilla href="http://bugzilla.redhat.com/127186" id="127186">CAN-2004-0758 Overriding built-in certificate leading to error -8182 (DoS), especially exploitable by email</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127338" id="127338">CAN-2004-0718 frame injection (spoofing) vuln in Mozilla before 1.7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129123" id="129123">Numerous security issues fixed in Mozilla 1.4.3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421002" comment="mozilla is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040434" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:434: redhat-config-nfs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-434.html" />
          <reference source="CVE" ref_id="CVE-2004-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0750.html" />
    
    <description>The redhat-config-nfs package includes a graphical user interface for
creating, modifying, and deleting nfs shares.

John Buswell discovered a flaw in redhat-config-nfs that could lead to
incorrect permissions on exported shares when exporting to multiple
hosts.  This could cause an option such as "all_squash" to not be
applied to all of the listed hosts.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0750 to
this issue.

Additionally, a bug was found that prevented redhat-config-nfs from being
run if hosts didn't have options set in /etc/exports.

All users of redhat-config-nfs are advised to upgrade to these updated
packages as well as checking their NFS shares directly or via the
/etc/exports file for any incorrectly set options.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-22" />
        <updated date="2004-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0750.html">CVE-2004-0750</cve>
                <bugzilla href="http://bugzilla.redhat.com/107997" id="107997">CVE-2004-0750 [PATCH] /etc/exports has incorrect syntax for multiple hosts with a single mount point</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040434002" comment="redhat-config-nfs is earlier than 0:1.0.13-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040434003" comment="redhat-config-nfs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040436" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:436: rsync security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-436.html" />
          <reference source="CVE" ref_id="CVE-2004-0792" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0792.html" />
    
    <description>The rsync program synchronizes files over a network. 
 
Versions of rsync up to and including version 2.6.2 contain a path 
sanitization issue.  This issue could allow an attacker to read or write 
files outside of the rsync directory.  This vulnerability is only 
exploitable when an rsync server is enabled and is not running within a
chroot. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0792 to this issue.

Users of rsync are advised to upgrade to this updated package, which 
contains a backported patch and is not affected by this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0792.html">CVE-2004-0792</cve>
                <bugzilla href="http://bugzilla.redhat.com/130050" id="130050">CAN-2004-0792 rsync path sanitizing bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040436002" comment="rsync is earlier than 0:2.5.7-5.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040441" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:441: ruby security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:441-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-441.html" />
          <reference source="CVE" ref_id="CVE-2004-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0755.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

Andres Salomon reported an insecure file permissions flaw in the CGI
session management of Ruby.  FileStore created world readable files that
could allow a malicious local user the ability to read CGI session data. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0755 to this issue.

Users are advised to upgrade to this erratum package, which contains a
backported patch to CGI::Session FileStore.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0755.html">CVE-2004-0755</cve>
                <bugzilla href="http://bugzilla.redhat.com/130065" id="130065">CAN-2004-0755 ruby insecure file permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441010" comment="irb is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441002" comment="ruby is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040446" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:446: openoffice.org security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:446-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-446.html" />
          <reference source="CVE" ref_id="CVE-2004-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0752.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Secunia Research reported an issue with the handling of temporary files.  A
malicious local user could use this flaw to access the contents of another
user's open documents.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0752 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0752.html">CVE-2004-0752</cve>
                <bugzilla href="http://bugzilla.redhat.com/130132" id="130132">CAN-2004-0752 openoffice temporary file information leakage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446006" comment="openoffice.org-i18n is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446002" comment="openoffice.org is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446004" comment="openoffice.org-libs is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040447" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:447: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:447-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-447.html" />
          <reference source="CVE" ref_id="CVE-2004-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0753.html" />
          <reference source="CVE" ref_id="CVE-2004-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0782.html" />
          <reference source="CVE" ref_id="CVE-2004-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0783.html" />
          <reference source="CVE" ref_id="CVE-2004-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0788.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

[Updated 15th September 2004]
Packages have been updated to correct a bug which caused the xpm loader
to fail.

During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was
discovered in the BMP image processor of gdk-pixbuf.  An attacker could
create a carefully crafted BMP file which would cause an application
to enter an infinite loop and not respond to user input when the file was
opened by a victim.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0753 to this issue.

During a security audit, Chris Evans discovered a stack and a heap overflow
in the XPM image decoder. An attacker could create a carefully crafted XPM
file which could cause an application linked with gtk2 to crash or possibly
execute arbitrary code when the file was opened by a victim.
(CAN-2004-0782, CAN-2004-0783)

Chris Evans also discovered an integer overflow in the ICO image decoder.
An attacker could create a carefully crafted ICO file which could cause an
application linked with gtk2 to crash when the file is opened by a victim.
(CAN-2004-0788)

These packages have also been updated to correct a bug which caused the xpm
loader to fail.

Users of gdk-pixbuf are advised to upgrade to these packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0753.html">CVE-2004-0753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0782.html">CVE-2004-0782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0783.html">CVE-2004-0783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0788.html">CVE-2004-0788</cve>
                <bugzilla href="http://bugzilla.redhat.com/130455" id="130455">CAN-2004-0753 bmp image loader DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130711" id="130711">CAN-2004-0782/3/8 GTK XPM decoder issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447002" comment="gdk-pixbuf is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040449" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:449: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-449.html" />
          <reference source="CVE" ref_id="CVE-2004-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0558.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

Alvaro Martinez Echevarria reported a bug in the CUPS Internet Printing
Protocol (IPP) implementation in versions of CUPS prior to 1.1.21.  An
attacker could send a carefully crafted UDP packet to the IPP port which
could cause CUPS to stop listening to the port and result in a denial of
service.  In order to exploit this bug, an attacker would need to have the
ability to send a UDP packet to the IPP port (by default 631).  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0558 to this issue.

All users of cups should upgrade to these updated packages, which contain a
backported patch as well as a fix for a non-exploitable off-by-one bug.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0558.html">CVE-2004-0558</cve>
                <bugzilla href="http://bugzilla.redhat.com/130650" id="130650">CAN-2004-0558 DOS in cups browsing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449004" comment="cups-devel is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449006" comment="cups-libs is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449002" comment="cups is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040451" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:451: spamassassin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-451.html" />
          <reference source="CVE" ref_id="CVE-2004-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0796.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug has been found in SpamAssassin versions below 2.64.
A malicious attacker could construct a message in such a way that would
cause spamassassin to stop responding, potentially preventing the delivery
or filtering of email.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0796 to this issue.

Users of SpamAssassin should update to these updated packages which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0796.html">CVE-2004-0796</cve>
                <bugzilla href="http://bugzilla.redhat.com/129337" id="129337">CAN-2004-0796 DOS attack open to certain malformed messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451002" comment="spamassassin is earlier than 0:2.55-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040462" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:462: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:462-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-462.html" />
          <reference source="CVE" ref_id="CVE-2004-0832" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0832.html" />
    
    <description>Squid is a full-featured Web proxy cache.

An out of bounds memory read bug was found within the NTLM authentication
helper routine.  If Squid is configured to use the NTLM authentication
helper, a remote attacker could send a carefully crafted NTLM
authentication packet and cause Squid to crash.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0832
to this issue.

Note: The NTLM authentication helper is not enabled by default in Red Hat
Enterprise Linux 3.  Red Hat Enterprise Linux 2.1 is not vulnerable to this
issue as it shipped with a version of Squid which did not contain the
vulnerable helper. 

Users of Squid should update to this erratum package, which contains a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0832.html">CVE-2004-0832</cve>
                <bugzilla href="http://bugzilla.redhat.com/131750" id="131750">CAN-2004-0832 Certain malformed NTLMSSP packets could crash the NTLM helpers provided by Squid</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040462002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040463" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:463: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:463-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-463.html" />
          <reference source="CVE" ref_id="CVE-2004-0747" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0747.html" />
          <reference source="CVE" ref_id="CVE-2004-0751" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0751.html" />
          <reference source="CVE" ref_id="CVE-2004-0786" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0786.html" />
          <reference source="CVE" ref_id="CVE-2004-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0809.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

Four issues have been discovered affecting releases of the Apache HTTP 2.0
Server, up to and including version 2.0.50:

Testing using the Codenomicon HTTP Test Tool performed by the Apache
Software Foundation security group and Red Hat uncovered an input
validation issue in the IPv6 URI parsing routines in the apr-util library. 
If a remote attacker sent a request including a carefully crafted URI, an
httpd child process could be made to crash.  This issue is not believed to
allow arbitrary code execution on Red Hat Enterprise Linux.  This issue
also does not represent a significant denial of service attack as requests
will continue to be handled by other Apache child processes.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0786 to this issue.

The Swedish IT Incident Centre (SITIC) reported a buffer overflow in the
expansion of environment variables during configuration file parsing.  This
issue could allow a local user to gain 'apache' privileges if an httpd
process can be forced to parse a carefully crafted .htaccess file written
by a local user.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0747 to this issue.

An issue was discovered in the mod_ssl module which could be triggered if
the server is configured to allow proxying to a remote SSL server.  A
malicious remote SSL server could force an httpd child process to crash by
sending a carefully crafted response header.  This issue is not believed to
allow execution of arbitrary code.  This issue also does not represent a
significant Denial of Service attack as requests will continue to be
handled by other Apache child processes.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0751 to
this issue.

An issue was discovered in the mod_dav module which could be triggered for
a location where WebDAV authoring access has been configured.  A malicious
remote client which is authorized to use the LOCK method could force an
httpd child process to crash by sending a particular sequence of LOCK
requests.  This issue does not allow execution of arbitrary code.  This
issue also does not represent a significant Denial of Service attack as
requests will continue to be handled by other Apache child processes.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0809 to this issue. 

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0747.html">CVE-2004-0747</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0751.html">CVE-2004-0751</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0786.html">CVE-2004-0786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0809.html">CVE-2004-0809</cve>
                <bugzilla href="http://bugzilla.redhat.com/131900" id="131900">CAN-2004-0747/51/86 Apache issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463004" comment="httpd-devel is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463006" comment="mod_ssl is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463002" comment="httpd is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040465" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:465: imlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-465.html" />
          <reference source="CVE" ref_id="CVE-2004-0817" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0817.html" />
    
    <description>Imlib is an image loading and rendering library.

Several heap overflow flaws were found in the imlib BMP image handler.   An
attacker could create a carefully crafted BMP file in such a way that it
could cause an application linked with imlib to execute arbitrary code when
the file was opened by a victim.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue.

Users of imlib should update to this updated package which contains
backported patches and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0817.html">CVE-2004-0817</cve>
                <bugzilla href="http://bugzilla.redhat.com/130909" id="130909">CAN-2004-0817 heap overflow in BMP decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465006" comment="imlib-cfgeditor is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465007" comment="imlib-cfgeditor is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465002" comment="imlib is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465003" comment="imlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465004" comment="imlib-devel is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465005" comment="imlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040466" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:466: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:466-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-466.html" />
          <reference source="CVE" ref_id="CVE-2004-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0753.html" />
          <reference source="CVE" ref_id="CVE-2004-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0782.html" />
          <reference source="CVE" ref_id="CVE-2004-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0783.html" />
          <reference source="CVE" ref_id="CVE-2004-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0788.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was
discovered in the BMP image processor of gtk2.  An attacker could create a
carefully crafted BMP file which would cause an application to enter an
infinite loop and not respond to user input when the file was opened by a
victim.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0753 to this issue.

During a security audit Chris Evans discovered a stack and a heap overflow
in the XPM image decoder.  An attacker could create a carefully crafted XPM
file which could cause an application linked with gtk2 to crash or possibly
execute arbitrary code when the file was opened by a victim. 
(CAN-2004-0782, CAN-2004-0783)

Chris Evans also discovered an integer overflow in the ICO image decoder. 
An attacker could create a carefully crafted ICO file which could cause an
application linked with gtk2 to crash when the file was opened by a victim.
(CAN-2004-0788)

This updated gtk2 package also fixes a few key combination bugs on various
X servers, such as Hummingbird, ReflectionX, and X-Win32. If a server was
configured to use the Swiss German, Swiss French, or France French keyboard
layouts, Mode_Switched characters were unable to be entered within GTK
based applications.

Users of gtk2 are advised to upgrade to these packages which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0753.html">CVE-2004-0753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0782.html">CVE-2004-0782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0783.html">CVE-2004-0783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0788.html">CVE-2004-0788</cve>
                <bugzilla href="http://bugzilla.redhat.com/130450" id="130450">CAN-2004-0753 bmp image loader DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130711" id="130711">CAN-2004-0782/3/8 GTK XPM decoder issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040466002" comment="gtk2 is earlier than 0:2.2.4-8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040466004" comment="gtk2-devel is earlier than 0:2.2.4-8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040467" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:467: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:467-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-467.html" />
          <reference source="CVE" ref_id="CVE-2004-0807" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0807.html" />
          <reference source="CVE" ref_id="CVE-2004-0808" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0808.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

The Samba team has discovered a denial of service bug in the smbd daemon. 
A defect in smbd's ASN.1 parsing allows an attacker to send a specially
crafted packet during the authentication request which will send the newly
spawned smbd process into an infinite loop.  Given enough of these packets,
it is possible to exhaust the available memory on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0807 to this issue.

Additionally the Samba team has also discovered a denial of service bug in
the nmbd daemon.  It is possible that an attacker could send a specially
crafted UDP packet which could allow the attacker to anonymously
crash nmbd.  This issue only affects nmbd daemons which are configured to
process domain logons.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0808 to this issue.

Users of Samba should upgrade to these updated packages, which contain an
upgrade to Samba-3.0.7, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-23" />
        <updated date="2004-09-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0807.html">CVE-2004-0807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0808.html">CVE-2004-0808</cve>
                <bugzilla href="http://bugzilla.redhat.com/132207" id="132207">CAN-2004-0807/8 Samba 3 DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467004" comment="samba-client is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467006" comment="samba-common is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467002" comment="samba is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467008" comment="samba-swat is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040478" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:478: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-478.html" />
          <reference source="CVE" ref_id="CVE-2004-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0419.html" />
          <reference source="CVE" ref_id="CVE-2004-0687" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0687.html" />
          <reference source="CVE" ref_id="CVE-2004-0688" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0688.html" />
          <reference source="CVE" ref_id="CVE-2004-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0692.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low level functionality which full fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

During a source code audit, Chris Evans discovered several stack overflow
flaws and an integer overflow flaw in the X.Org libXpm library used to
decode XPM (X PixMap) images. An attacker could create a carefully crafted
XPM file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687,
CAN-2004-0688, and CAN-2004-0692 to these issues.

A flaw was found in the X Display Manager (XDM). XDM is shipped with Red
Hat Enterprise Linux, but is not used by default. XDM opened a chooserFd
TCP socket even if the DisplayManager.requestPort parameter was set to 0.
This allowed authorized users to access a machine remotely via X, even if
the administrator had configured XDM to refuse such connections. Although
XFree86 4.3.0 was not vulnerable to this issue, Red Hat Enterprise Linux 3
contained a backported patch which introduced this flaw. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0419 to this issue.

Users are advised to upgrade to these erratum packages, which contain
backported security patches to correct these and a number of other issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-04" />
        <updated date="2004-10-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0419.html">CVE-2004-0419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0687.html">CVE-2004-0687</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0688.html">CVE-2004-0688</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0692.html">CVE-2004-0692</cve>
                <bugzilla href="http://bugzilla.redhat.com/124901" id="124901">CAN-2004-0419 xdm opens random tcp sockets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126205" id="126205">xdm walks physical memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129744" id="129744">Radeon driver (7000m) TVDAC output too high for DELL Server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131121" id="131121">CAN-2004-0687/8 libXpm stack and integer overflows.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132121" id="132121">archexec script not in XFree86-devel package</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478012" comment="XFree86-xdm is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478016" comment="XFree86-libs-data is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478058" comment="XFree86-doc is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478002" comment="XFree86 is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478054" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478014" comment="XFree86-libs is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478060" comment="XFree86-sdk is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478008" comment="XFree86-xfs is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478046" comment="XFree86-Xnest is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478056" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478018" comment="XFree86-base-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478006" comment="XFree86-font-utils is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478050" comment="XFree86-tools is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478048" comment="XFree86-Xvfb is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478010" comment="XFree86-twm is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478052" comment="XFree86-xauth is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478004" comment="XFree86-devel is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040480" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:480: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-480.html" />
          <reference source="CVE" ref_id="CVE-2004-0827" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0827.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System.

A heap overflow flaw has been discovered in the ImageMagick image handler.
An attacker could create a carefully crafted BMP file in such a way that it
could cause ImageMagick to execute arbitrary code when processing the
image.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0827 to this issue.

Users of ImageMagick should upgrade to this updated package, which contains
a backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0827.html">CVE-2004-0827</cve>
                <bugzilla href="http://bugzilla.redhat.com/130807" id="130807">CAN-2004-0827 heap overflow in BMP decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480004" comment="ImageMagick-devel is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480006" comment="ImageMagick-perl is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480002" comment="ImageMagick is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480008" comment="ImageMagick-c++ is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040486" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:486: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-486.html" />
          <reference source="CVE" ref_id="CVE-2004-0902" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0902.html" />
          <reference source="CVE" ref_id="CVE-2004-0903" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0903.html" />
          <reference source="CVE" ref_id="CVE-2004-0904" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0904.html" />
          <reference source="CVE" ref_id="CVE-2004-0905" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0905.html" />
          <reference source="CVE" ref_id="CVE-2004-0908" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0908.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Jesse Ruderman discovered a cross-domain scripting bug in Mozilla.  If
a user is tricked into dragging a javascript link into another frame or
page, it becomes possible for an attacker to steal or modify sensitive
information from that site.  Additionally, if a user is tricked into
dragging two links in sequence to another window (not frame), it is
possible for the attacker to execute arbitrary commands.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0905 to this issue.

Gael Delalleau discovered an integer overflow which affects the BMP
handling code inside Mozilla. An attacker could create a carefully crafted
BMP file in such a way that it would cause Mozilla to crash or execute
arbitrary code when the image is viewed.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0904 to
this issue.

Georgi Guninski discovered a stack-based buffer overflow in the vCard
display routines.  An attacker could create a carefully crafted vCard file
in such a way that it would cause Mozilla to crash or execute arbitrary
code when viewed.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0903 to this issue.

Wladimir Palant discovered a flaw in the way javascript interacts with
the clipboard.  It is possible that an attacker could use malicious
javascript code to steal sensitive data which has been copied into the
clipboard.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0908 to this issue.

Georgi Guninski discovered a heap based buffer overflow in the "Send
Page" feature.  It is possible that an attacker could construct a link in
such a way that a user attempting to forward it could result in a crash or
arbitrary code execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0902 to this issue.

Users of Mozilla should update to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0902.html">CVE-2004-0902</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0903.html">CVE-2004-0903</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0904.html">CVE-2004-0904</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0905.html">CVE-2004-0905</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0908.html">CVE-2004-0908</cve>
                <bugzilla href="http://bugzilla.redhat.com/133012" id="133012">CAN-2004-0905 javascript link dragging information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133013" id="133013">CAN-2004-0905 javascript link dragging information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133014" id="133014">CAN-2004-0904 BMP integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133015" id="133015">CAN-2004-0904 BMP integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133016" id="133016">CAN-2004-0903 VCard buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133017" id="133017">CAN-2004-0903 VCard buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133021" id="133021">CAN-2004-0908 javascript clipboard information leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133022" id="133022">CAN-2004-0908 javascript clipboard information leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133023" id="133023">CAN-2004-0902 "send page" heap based buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133024" id="133024">CAN-2004-0902 "send page" heap based buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486002" comment="mozilla is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040489" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:489: rh-postgresql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:489-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-489.html" />
          <reference source="CVE" ref_id="CVE-2004-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0977.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS) that supports almost all SQL constructs (including transactions,
subselects, and user-defined types and functions).

Trustix has identified improper temporary file usage in the
make_oidjoins_check script.  It is possible that an attacker could
overwrite arbitrary file contents as the user running the
make_oidjoins_check script.  This script has been removed from the RPM file
since it has no use to ordinary users.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0977 to
this issue.

Additionally, the following non-security issues have been addressed:

- Fixed a low probability risk for loss of recently committed transactions.

- Fixed a low probability risk for loss of older data due to failure to 
  update transaction status.

- A lock file problem that sometimes prevented automatic restart after a 
  system crash has been fixed.

All users of rh-postgresql should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0977.html">CVE-2004-0977</cve>
                <bugzilla href="http://bugzilla.redhat.com/130814" id="130814">PostgreSQL can lose committed transactions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130989" id="130989">a bug in rh-postgresql.spec file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134090" id="134090">Postgres's init script does not remove stale PID file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136300" id="136300">CAN-2004-0977 temporary file vulnerabilities in make_oidjoins_check script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136949" id="136949">PostgreSQL data loss risk and minor security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489020" comment="rh-postgresql-jdbc is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489008" comment="rh-postgresql-docs is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489010" comment="rh-postgresql-contrib is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489002" comment="rh-postgresql is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489018" comment="rh-postgresql-python is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489014" comment="rh-postgresql-pl is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489012" comment="rh-postgresql-devel is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489022" comment="rh-postgresql-test is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489016" comment="rh-postgresql-tcl is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489006" comment="rh-postgresql-server is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489004" comment="rh-postgresql-libs is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040537" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:537: openmotif security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:537-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-537.html" />
          <reference source="CVE" ref_id="CVE-2004-0687" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0687.html" />
          <reference source="CVE" ref_id="CVE-2004-0688" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0688.html" />
          <reference source="CVE" ref_id="CVE-2004-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0914.html" />
    
    <description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.  

During a source code audit, Chris Evans and others discovered several stack
overflow flaws and an integer overflow flaw in the libXpm library used to
decode XPM (X PixMap) images. A vulnerable version of this library was
found within OpenMotif. An attacker could create a carefully crafted
XPM file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names
CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.

Users of OpenMotif are advised to upgrade to these erratum packages, which
contain backported security patches to the embedded libXpm library.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-02" />
        <updated date="2004-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0687.html">CVE-2004-0687</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0688.html">CVE-2004-0688</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0914.html">CVE-2004-0914</cve>
                <bugzilla href="http://bugzilla.redhat.com/134631" id="134631">CAN-2004-0687 libxpm flaws affect OpenMotif (CAN-2004-0688, CAN-2004-0914)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537004" comment="openmotif-devel is earlier than 0:2.2.3-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537002" comment="openmotif is earlier than 0:2.2.3-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537006" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040543" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:543: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:543-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-543.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-0923" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0923.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect xpdf.  CUPS contains a copy of the xpdf code used
for parsing PDF files and is therefore affected by these bugs.  An attacker
who has the ability to send a malicious PDF file to a printer could cause
CUPS to crash or possibly execute arbitrary code.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0888 to this issue.

When set up to print to a shared printer via Samba, CUPS would authenticate
with that shared printer using a username and password.  By default, the
username and password used to connect to the Samba share is written
into the error log file.  A local user who is able to read the error log
file could collect these usernames and passwords.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0923 to this issue.

These updated packages also include a fix that prevents some CUPS
configuration files from being accidentally replaced.

All users of CUPS should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-22" />
        <updated date="2004-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0923.html">CVE-2004-0923</cve>
                <bugzilla href="http://bugzilla.redhat.com/99461" id="99461">cups configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132034" id="132034">mime.types was updated - not copied to mime.types.rpmnew</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134599" id="134599">CAN-2004-0923 Log file information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135378" id="135378">CAN-2004-0888 xpdf issues affect cups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543004" comment="cups-devel is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543006" comment="cups-libs is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543002" comment="cups is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040546" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:546: cyrus-sasl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:546-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-546.html" />
          <reference source="CVE" ref_id="CVE-2004-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0884.html" />
    
    <description>The cyrus-sasl package contains the Cyrus implementation of SASL.  SASL is
the Simple Authentication and Security Layer, a method for adding
authentication support to connection-based protocols.

At application startup, libsasl and libsasl2 attempts to build a list
of all available SASL plug-ins which are available on the system.  To do
so, the libraries search for and attempt to load every shared library found
within the plug-in directory.  This location can be set with the SASL_PATH
environment variable.

In situations where an untrusted local user can affect the environment of a
privileged process, this behavior could be exploited to run arbitrary code
with the privileges of a setuid or setgid application.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0884 to this issue.

Users of cyrus-sasl should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-07" />
        <updated date="2004-10-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0884.html">CVE-2004-0884</cve>
                <bugzilla href="http://bugzilla.redhat.com/134657" id="134657">CAN-2004-0884 privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134979" id="134979">cyrus-sasl causes crashes with ldap</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546008" comment="cyrus-sasl-plain is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546009" comment="cyrus-sasl-plain is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546004" comment="cyrus-sasl-devel is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546005" comment="cyrus-sasl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546010" comment="cyrus-sasl-md5 is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546011" comment="cyrus-sasl-md5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546006" comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546007" comment="cyrus-sasl-gssapi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546002" comment="cyrus-sasl is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546003" comment="cyrus-sasl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040549" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:549: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-549.html" />
          <reference source="CVE" ref_id="CVE-2004-0138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0138.html" />
          <reference source="CVE" ref_id="CVE-2004-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0619.html" />
          <reference source="CVE" ref_id="CVE-2004-0685" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0685.html" />
          <reference source="CVE" ref_id="CVE-2004-0812" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0812.html" />
          <reference source="CVE" ref_id="CVE-2004-0883" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0883.html" />
          <reference source="CVE" ref_id="CVE-2004-0949" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0949.html" />
          <reference source="CVE" ref_id="CVE-2004-1068" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1068.html" />
          <reference source="CVE" ref_id="CVE-2004-1070" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1070.html" />
          <reference source="CVE" ref_id="CVE-2004-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1071.html" />
          <reference source="CVE" ref_id="CVE-2004-1072" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1072.html" />
          <reference source="CVE" ref_id="CVE-2004-1073" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1073.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This update includes fixes for several security issues:

A missing serialization flaw in unix_dgram_recvmsg was discovered that
affects kernels prior to 2.4.28.  A local user could potentially make
use of a race condition in order to gain privileges.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1068 to this issue.

Paul Starzetz of iSEC discovered various flaws in the ELF binary
loader affecting kernels prior to 2.4.28.  A local user could use thse
flaws to gain read access to executable-only binaries or possibly gain
privileges. (CAN-2004-1070, CAN-2004-1071, CAN-2004-1072, CAN-2004-1073)

A flaw when setting up TSS limits was discovered that affects AMD AMD64
and Intel EM64T architecture kernels prior to 2.4.23.  A local user could
use this flaw to cause a denial of service (crash) or possibly gain
privileges.  (CAN-2004-0812)

An integer overflow flaw was discovered in the ubsec_keysetup function
in the Broadcom 5820 cryptonet driver.  On systems using this driver,
a local user could cause a denial of service (crash) or possibly gain
elevated privileges.  (CAN-2004-0619)

Stefan Esser discovered various flaws including buffer overflows in
the smbfs driver affecting kernels prior to 2.4.28.  A local user may be
able to cause a denial of service (crash) or possibly gain privileges.
In order to exploit these flaws the user would require control of
a connected Samba server.  (CAN-2004-0883, CAN-2004-0949)

SGI discovered a bug in the elf loader that affects kernels prior to
2.4.25 which could be triggered by a malformed binary.  On
architectures other than x86, a local user could create a malicious
binary which could cause a denial of service (crash).  (CAN-2004-0136)

Conectiva discovered flaws in certain USB drivers affecting kernels
prior to 2.4.27 which used the copy_to_user function on uninitialized
structures.  These flaws could allow local users to read small amounts
of kernel memory.  (CAN-2004-0685)

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-02" />
        <updated date="2004-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0138.html">CVE-2004-0138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0619.html">CVE-2004-0619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0685.html">CVE-2004-0685</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0812.html">CVE-2004-0812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0883.html">CVE-2004-0883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0949.html">CVE-2004-0949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1068.html">CVE-2004-1068</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1070.html">CVE-2004-1070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1071.html">CVE-2004-1071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1072.html">CVE-2004-1072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1073.html">CVE-2004-1073</cve>
                <bugzilla href="http://bugzilla.redhat.com/127258" id="127258">CAN-2004-0619 Broadcom 5820 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127915" id="127915">CAN-2004-0138 Verify interpreter arch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127918" id="127918">CAN-2004-0685 usb sparse fixes in 2.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134720" id="134720">CAN-2004-0883 smbfs potential DOS (CAN-2004-0949)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134874" id="134874">CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134981" id="134981">CAN-2004-0138 Program crashes the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140710" id="140710">CAN-2004-1068 Missing serialisation in unix_dgram_recvmsg</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549004" comment="kernel-source is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549002" comment="kernel is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549006" comment="kernel-doc is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549014" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549016" comment="kernel-hugemem is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549018" comment="kernel-BOOT is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549008" comment="kernel-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549012" comment="kernel-smp is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040562" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:562: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:562-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-562.html" />
          <reference source="CVE" ref_id="CVE-2004-0885" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0885.html" />
          <reference source="CVE" ref_id="CVE-2004-0942" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0942.html" />
          <reference source="CVE" ref_id="CVE-2004-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1834.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue has been discovered in the mod_ssl module when configured to use
the "SSLCipherSuite" directive in directory or location context.  If a
particular location context has been configured to require a specific set
of cipher suites, then a client will be able to access that location using
any cipher suite allowed by the virtual host configuration.   The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0885 to this issue.

An issue has been discovered in the handling of white space in request
header lines using MIME folding.  A malicious client could send a carefully
crafted request, forcing the server to consume large amounts of memory,
leading to a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0942 to this issue.

Several minor bugs were also discovered, including:

- In the mod_cgi module, problems that arise when CGI scripts are 
  invoked from SSI pages by mod_include using the "#include virtual" 
  syntax have been fixed.

- In the mod_dav_fs module, problems with the handling of indirect locks
  on the S/390x platform have been fixed.

Users of the Apache HTTP server who are affected by these issues should
upgrade to these updated packages, which contain backported patches.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0885.html">CVE-2004-0885</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0942.html">CVE-2004-0942</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1834.html">CVE-2004-1834</cve>
                <bugzilla href="http://bugzilla.redhat.com/134825" id="134825">CAN-2004-0885 SSLCipherSuite bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138064" id="138064">CAN-2004-0942 Memory consumption DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562004" comment="httpd-devel is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562006" comment="mod_ssl is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562002" comment="httpd is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040569" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:569: mysql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-569.html" />
          <reference source="CVE" ref_id="CVE-2004-0381" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0381.html" />
          <reference source="CVE" ref_id="CVE-2004-0388" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0388.html" />
          <reference source="CVE" ref_id="CVE-2004-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0457.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes a number of small bugs, including some potential
security problems associated with careless handling of temporary files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0381, CAN-2004-0388, and CAN-2004-0457 to these
issues.

A number of additional security issues that affect mysql have been
corrected in the source package.  These include CAN-2004-0835,
CAN-2004-0836, CAN-2004-0837, and CAN-2004-0957.  Red Hat Enterprise Linux
3 does not ship with the mysql-server package and is therefore not affected
by these issues.

This update also allows 32-bit and 64-bit libraries to be installed
concurrently on the same system.

All users of mysql should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0381.html">CVE-2004-0381</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0388.html">CVE-2004-0388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0457.html">CVE-2004-0457</cve>
                <bugzilla href="http://bugzilla.redhat.com/58732" id="58732">/etc/init.d/mysqld doesn't wait for server to start</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108779" id="108779">Always timeout error starting MySQL Daemon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112693" id="112693">mysqlhotcopy of local Fedora DB broken after upgrade from RH9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113960" id="113960">[PATCH] Bug fix + enhancement for mysql_setpermission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115165" id="115165">botched string concat ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119442" id="119442">CAN-2004-0381 mysqlbug temporary file vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124352" id="124352">Cannot drop databases</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128852" id="128852">database service should start earlier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129409" id="129409">linking with 'mysql --libs' doesent seem to work correctly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130348" id="130348">CAN-2004-0457 mysqlhotcopy insecure temporary file vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133993" id="133993">Service mysqld restart</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135387" id="135387">CAN-2004-0835 MySQL flaws (CAN-2004-0836, CAN-2004-0837, CAN-2004-0957)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569002" comment="mysql is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569004" comment="mysql-server is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569008" comment="mysql-bench is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569006" comment="mysql-devel is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040577" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:577: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:577-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-577.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1307.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files. TIFF is a widely used file
format for bitmapped images. 

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. An attacker who has the ability to trick
a user into opening a malicious TIFF file could cause the application
linked to libtiff to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found.  An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause the application linked to libtiff to crash
or possibly execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0803 to
this issue.

All users are advised to upgrade to these errata packages, which contain
fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-22" />
        <updated date="2004-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1307.html">CVE-2004-1307</cve>
                <bugzilla href="http://bugzilla.redhat.com/134847" id="134847">CAN-2004-0803 buffer overflows in libtiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134850" id="134850">CAN-2004-0886 multiple integer overflows in libtiff</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040577002" comment="libtiff is earlier than 0:3.5.7-20.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040577004" comment="libtiff-devel is earlier than 0:3.5.7-20.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040583" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:583: nfs-utils security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:583-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-583.html" />
          <reference source="CVE" ref_id="CVE-2004-1014" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1014.html" />
          <reference source="CVE" ref_id="CVE-2004-0946" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0946.html" />
    
    <description>The nfs-utils package provides a daemon for the kernel NFS server and
related tools, providing a much higher level of performance than the
traditional Linux NFS server used by most users.

This package also contains the showmount program. Showmount queries
the mount daemon on a remote host for information about the NFS
(Network File System) server on the remote host.

SGI reported that the statd daemon did not properly handle the SIGPIPE
signal.  A misconfigured or malicious peer could cause statd to crash,
leading to a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1014 to this issue.

Arjan van de Ven discovered a buffer overflow in rquotad.  On 64-bit
architectures, an improper integer conversion can lead to a buffer
overflow.  An attacker with access to an NFS share could send a specially
crafted request which could lead to the execution of arbitrary code.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0946 to this issue.

Additionally, this updated package addresses the following issues:

- The UID of the nfsnobody account has been fixed for 32-bit and 64-bit
machines. Because the st_uid field of the stat structure is an unsigned
integer, an actual value of -2 cannot be used when creating the account, so
the decimal value of -2 is used. On a 32-bit machine, the decimal value of
-2 is 65534 but on a 64-bit machine it is 4294967294. This errata enables
the nfs-utils post-install script to detect the target architecture, so an
appropriate decimal value is used.

All users of nfs-utils should upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1014.html">CVE-2004-1014</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0946.html">CVE-2004-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/139611" id="139611">CAN-2004-1014 DoS in statd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040583002" comment="nfs-utils is earlier than 0:1.0.6-33EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072003" comment="nfs-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040585" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:585: xchat security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:585-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-585.html" />
          <reference source="CVE" ref_id="CVE-2004-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0409.html" />
    
    <description>X-Chat is a graphical IRC chat client for the X Window System.

A stack buffer overflow has been fixed in the SOCKSv5 proxy code.
An attacker could create a malicious SOCKSv5 proxy server in such a way
that X-Chat would execute arbitrary code if a victim configured X-Chat to
use the proxy.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0409 to this issue.

Users of X-Chat should upgrade to this erratum package, which contains a
backported security patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-27" />
        <updated date="2004-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0409.html">CVE-2004-0409</cve>
                <bugzilla href="http://bugzilla.redhat.com/121333" id="121333">CAN-2004-0409 XChat buffer overflow in socks5 proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135238" id="135238">CAN-2004-0409 XChat buffer overflow in socks5 proxy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040585002" comment="xchat is earlier than 1:2.0.4-4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040585003" comment="xchat is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040586" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:586: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-586.html" />
          <reference source="CVE" ref_id="CVE-2004-0968" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0968.html" />
    
    <description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

This errata fixes several bugs in the GNU C Library.

Fixes include (in addition to enclosed Bugzilla entries):

- fixed 32-bit atomic operations on 64-bit powerpc
- fixed -m32 -I /usr/include/nptl compilation on AMD64
- NPTL &lt;pthread.h> should now be usable in C++ code or -pedantic -std=c89 C
- rwlocks are now available also in the _POSIX_C_SOURCE=200112L namespace
- pthread_once is no longer throw(), as the callback routine might throw
- pthread_create now correctly returns EAGAIN when thread couldn't be
created because of lack of memory
- fixed NPTL stack freeing in case of pthread_create failure with detached
thread
- fixed pthread_mutex_timedlock on i386 and AMD64
- Itanium gp saving fix in linuxthreads
- fixed s390/s390x unwinding tests done during cancellation if stack frames
are small
- fixed fnmatch(3) backslash handling
- fixed out of memory behaviour of syslog(3)
- resolver ID randomization
- fixed fim (NaN, NaN)
- glob(3) fixes for dangling symlinks
- catchsegv fixed to work with both 32-bit and 64-bit binaries on x86-64,
s390x and ppc
- fixed reinitialization of _res when using NPTL stack cache
- updated bug reporting instructions, removed glibcbug script
- fixed infinite loop in iconv with some options
- fixed inet_aton return value
- CPU friendlier busy waiting in linuxthreads on EM64T and IA-64
- avoid blocking/masking debug signal in linuxthreads
- fixed locale program output when neither LC_ALL nor LANG is set
- fixed using of unitialized memory in localedef
- fixed mntent_r escape processing
- optimized mtrace script
- linuxthread_db fixes on ppc64
- cfi instructions in x86-64 linuxthreads vfork
- some _POSIX_C_SOURCE=200112L namespace fixes

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0968.html">CVE-2004-0968</cve>
                <bugzilla href="http://bugzilla.redhat.com/103415" id="103415">Weird string in date printing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118574" id="118574">malloc exhausts memory to fast in mulithreaded program</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123583" id="123583">getnameinfo does not use /etc/hosts for lookup of V4MAPPED addresses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127606" id="127606">__builtin_expect's prototype does not expect int args; assert feeds it just that</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130254" id="130254">glibc's traceback() fails when called from an exception handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132204" id="132204">glibc-nis-performance.patch causes gdm to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132816" id="132816">glibc in RHEL 3 needs to have syslog.c updated to cvs version 1.42</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136318" id="136318">CAN-2004-0968 temporary file vulnerabilities in catchsegv script</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586012" comment="glibc-common is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586006" comment="glibc-headers is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586008" comment="nptl-devel is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586004" comment="glibc-devel is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586016" comment="glibc-debug is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586010" comment="glibc-profile is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586002" comment="glibc is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586014" comment="nscd is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586018" comment="glibc-utils is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040591" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:591: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:591-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-591.html" />
          <reference source="CVE" ref_id="CVE-2004-0918" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0918.html" />
    
    <description>Squid is a full-featured Web proxy cache.

iDEFENSE reported a flaw in the squid SNMP module.  This flaw could allow
an attacker who has the ability to send arbitrary packets to the SNMP port
to restart the server, causing it to drop all open connections.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0918 to this issue.

All users of squid should update to this erratum package, which contains a
backport of the security fix for this vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0918.html">CVE-2004-0918</cve>
                <bugzilla href="http://bugzilla.redhat.com/135319" id="135319">CAN-2004-0918 SNMP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040591002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040592" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:592: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:592-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-592.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format
(PDF) files.

During a source code audit, Chris Evans and others discovered a number
of integer overflow bugs that affected all versions of xpdf.  An
attacker could construct a carefully crafted PDF file that could cause
xpdf to crash or possibly execute arbitrary code when opened.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0888 to this issue.

Users of xpdf are advised to upgrade to this errata package, which contains
a backported patch correcting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-27" />
        <updated date="2004-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
                <bugzilla href="http://bugzilla.redhat.com/135393" id="135393">CAN-2004-0888 xpdf integer overflows (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592002" comment="xpdf is earlier than 1:2.02-9.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040604" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:604: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:604-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-604.html" />
          <reference source="CVE" ref_id="CVE-2004-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0891.html" />
    
    <description>The gaim application is a multi-protocol instant messaging client.

A buffer overflow has been discovered in the MSN protocol handler.  When
receiving unexpected sequence of MSNSLP messages, it is possible that an
attacker could cause an internal buffer overflow, leading to a crash or
possible code execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0891 to this issue.

This updated gaim package also fixes multiple user interface, protocol, and
error handling problems, including an ICQ communication encoding issue.

Additionally, these updated packages have compiled gaim as a PIE (position
independent executable) for added protection against future security
vulnerabilities.

All users of gaim should upgrade to this updated package, which includes
various bug fixes, as well as a backported security patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0891.html">CVE-2004-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/135678" id="135678">CAN-2004-0891 MSN protocol buffer overflow.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040604002" comment="gaim is earlier than 1:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040609" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:609: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:609-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-609.html" />
          <reference source="CVE" ref_id="CVE-2004-0938" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0938.html" />
          <reference source="CVE" ref_id="CVE-2004-0960" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0960.html" />
          <reference source="CVE" ref_id="CVE-2004-0961" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0961.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A number of flaws were found in FreeRADIUS versions prior to 1.0.1.  An
attacker who is able to send packets to the server could construct
carefully constructed packets in such a way as to cause the server to
consume memory or crash.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2004-0938, CAN-2004-0960, and
CAN-2004-0961 to these issues.

Users of FreeRADIUS should update to these erratum packages that contain
FreeRADIUS 1.0.1, which is not vulnerable to these issues and also corrects
a number of bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0938.html">CVE-2004-0938</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0960.html">CVE-2004-0960</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0961.html">CVE-2004-0961</cve>
                <bugzilla href="http://bugzilla.redhat.com/127162" id="127162">zlib-devel is missing from BuildRequires in spec file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127168" id="127168">rebuilding freeradius picks up system libeap rather than package libeap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130606" id="130606">Missing buildrequires in freediag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130613" id="130613">radiusd.conf specifies other pam-auth than file installed in /etc/pam.d</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135825" id="135825">CAN-2004-0938 Freeradius &lt; 1.0.1 DoS and remote crash (CAN-2004-0960, CAN-2004-0961)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609004" comment="freeradius-mysql is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609006" comment="freeradius-postgresql is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609008" comment="freeradius-unixODBC is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609002" comment="freeradius is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040612" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:612: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:612-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-612.html" />
          <reference source="CVE" ref_id="CVE-2004-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0914.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low level functionality which full fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow flaws in the X.Org libXpm library used to decode
XPM (X PixMap) images have been found and addressed. An attacker could
create a carefully crafted XPM file which would cause an application to
crash or potentially execute arbitrary code if opened by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0914 to this issue.

Users are advised to upgrade to these erratum packages, which contain
backported security patches as well as other bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0914.html">CVE-2004-0914</cve>
                <bugzilla href="http://bugzilla.redhat.com/136164" id="136164">CAN-2004-0914 libXpm integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612012" comment="XFree86-xdm is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612016" comment="XFree86-libs-data is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612058" comment="XFree86-doc is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612002" comment="XFree86 is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612054" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612014" comment="XFree86-libs is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612060" comment="XFree86-sdk is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612008" comment="XFree86-xfs is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612046" comment="XFree86-Xnest is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612056" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612018" comment="XFree86-base-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612006" comment="XFree86-font-utils is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612050" comment="XFree86-tools is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612048" comment="XFree86-Xvfb is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612010" comment="XFree86-twm is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612052" comment="XFree86-xauth is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612004" comment="XFree86-devel is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040615" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:615: libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:615-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-615.html" />
          <reference source="CVE" ref_id="CVE-2004-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0989.html" />
    
    <description>libxml2 is a library for manipulating XML files.

Multiple buffer overflow bugs have been found in libxml2 versions prior to
2.6.14.  If an attacker can trick a user into passing a specially crafted
FTP URL or FTP proxy URL to an application that uses the vulnerable
functions of libxml2, it could be possible to execute arbitrary code.  
Additionally, if an attacker can return a specially crafted DNS request to
libxml2, it could be possible to execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0989 to this issue.

All users are advised to upgrade to this updated package, which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0989.html">CVE-2004-0989</cve>
                <bugzilla href="http://bugzilla.redhat.com/137264" id="137264">CAN-2004-0989 multiple buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615002" comment="libxml2 is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090003" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615004" comment="libxml2-devel is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090005" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615006" comment="libxml2-python is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090007" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040632" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:632: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:632-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-632.html" />
          <reference source="CVE" ref_id="CVE-2004-0882" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0882.html" />
          <reference source="CVE" ref_id="CVE-2004-0930" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0930.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

During a code audit, Stefan Esser discovered a buffer overflow in Samba
versions prior to 3.0.8 when handling unicode filenames.  An authenticated
remote user could exploit this bug which may lead to arbitrary code
execution on the server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0882 to this issue. Red Hat
believes that the Exec-Shield technology (enabled by default since Update
3) will block attempts to remotely exploit this vulnerability on x86
architectures.

Additionally, a bug was found in the input validation routines in versions
of Samba prior to 3.0.8 that caused the smbd process to consume abnormal
amounts of system memory.  An authenticated remote user could exploit this
bug to cause a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0930 to this issue.

Users of Samba should upgrade to these updated packages, which contain
backported security patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-16" />
        <updated date="2004-11-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0882.html">CVE-2004-0882</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0930.html">CVE-2004-0930</cve>
                <bugzilla href="http://bugzilla.redhat.com/134640" id="134640">CAN-2004-0882 unicode parsing overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138325" id="138325">CAN-2004-0930 wildcard remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632004" comment="samba-client is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632006" comment="samba-common is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632002" comment="samba is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632008" comment="samba-swat is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040634" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:634: zip security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:634-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-634.html" />
          <reference source="CVE" ref_id="CVE-2004-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1010.html" />
    
    <description>The zip program is an archiving utility which can create ZIP-compatible
archives.

A buffer overflow bug has been discovered in zip when handling long file
names.  An attacker could create a specially crafted path which could
cause zip to crash or execute arbitrary instructions.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1010 to this issue.

Users of zip should upgrade to this updated package, which contains
backported patches and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2004-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1010.html">CVE-2004-1010</cve>
                <bugzilla href="http://bugzilla.redhat.com/138228" id="138228">CAN-2004-1010 buffer overflow when creating archive containing very long filenames.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040634002" comment="zip is earlier than 0:2.3-16.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040634003" comment="zip is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040635" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:635: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:635-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-635.html" />
          <reference source="CVE" ref_id="CVE-2004-0983" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0983.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A flaw was dicovered in the CGI module of Ruby.  If empty data is sent by
the POST method to the CGI script which requires MIME type
multipart/form-data, it can get stuck in a loop.  A remote attacker could
trigger this flaw and cause a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0983 to this issue.

Users are advised to upgrade to this erratum package, which contains a
backported patch to cgi.rb.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-17" />
        <updated date="2005-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0983.html">CVE-2004-0983</cve>
                <bugzilla href="http://bugzilla.redhat.com/138362" id="138362">CAN-2004-0983 Denial of Service in Ruby</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635010" comment="irb is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635002" comment="ruby is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040636" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:636: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:636-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-636.html" />
          <reference source="CVE" ref_id="CVE-2004-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0981.html" />
          <reference source="CVE" ref_id="CVE-2004-0827" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0827.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System.

A buffer overflow flaw was discovered in the ImageMagick image handler.
An attacker could create a carefully crafted image file with an improper
EXIF information in such a way that it would cause ImageMagick to execute
arbitrary code when processing the image. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0981 to
this issue.

David Eisenstein has reported that our previous fix for CAN-2004-0827, a
heap overflow flaw, was incomplete.  An attacker could create a carefully
crafted BMP file in such a way that it could cause ImageMagick to execute
arbitrary code when processing the image. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0827 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-08" />
        <updated date="2004-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0981.html">CVE-2004-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0827.html">CVE-2004-0827</cve>
                <bugzilla href="http://bugzilla.redhat.com/130807" id="130807">CAN-2004-0827 heap overflow in BMP decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138383" id="138383">CAN-2004-0981 buffer overflow in ImageMagick's EXIF parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636004" comment="ImageMagick-devel is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636006" comment="ImageMagick-perl is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636002" comment="ImageMagick is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636008" comment="ImageMagick-c++ is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040638" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:638: gd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:638-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-638.html" />
          <reference source="CVE" ref_id="CVE-2004-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0941.html" />
          <reference source="CVE" ref_id="CVE-2004-0990" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0990.html" />
    
    <description>The gd packages contain a graphics library used for the dynamic creation of
images such as PNG and JPEG. 

Several buffer overflows were reported in various memory allocation calls.
An attacker could create a carefully crafted image file in such a way that
it could cause ImageMagick to execute arbitrary code when processing the
image. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0990 to these issues.  

While researching the fixes to these overflows, additional buffer overflows
were discovered in calls to gdMalloc.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0941 to
these issues.  

Users of gd should upgrade to these updated packages, which contain a
backported security patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2005-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0941.html">CVE-2004-0941</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0990.html">CVE-2004-0990</cve>
                <bugzilla href="http://bugzilla.redhat.com/137246" id="137246">CAN-2004-0990 integer overflow in PNG handling.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138808" id="138808">CAN-2004-0941 additional overflows in gd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638006" comment="gd-devel is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638007" comment="gd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638004" comment="gd-progs is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638005" comment="gd-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638002" comment="gd is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638003" comment="gd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040650" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:650: libxml security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:650-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-650.html" />
          <reference source="CVE" ref_id="CVE-2004-0110" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0110.html" />
          <reference source="CVE" ref_id="CVE-2004-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0989.html" />
    
    <description>The libxml package contains a library for manipulating XML files.

Multiple buffer overflow bugs have been found in libxml versions prior to
2.6.14.  If an attacker can trick a user into passing a specially crafted
FTP URL or FTP proxy URL to an application that uses the vulnerable
functions of libxml, it could be possible to execute arbitrary code.  
Additionally, if an attacker can return a specially crafted DNS request to
libxml, it could be possible to execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0989 to this issue.

Yuuichi Teranishi discovered a flaw in libxml versions prior to 2.6.6.
When fetching a remote resource via FTP or HTTP, libxml uses special
parsing routines. These routines can overflow a buffer if passed a very
long URL. If an attacker is able to find an application using libxml that
parses remote resources and allows them to influence the URL, then this
flaw could be used to execute arbitrary code. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0110
to this issue.

All users are advised to upgrade to this updated package, which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2005-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0110.html">CVE-2004-0110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0989.html">CVE-2004-0989</cve>
                <bugzilla href="http://bugzilla.redhat.com/139090" id="139090">CAN-2004-0110 multiple buffer overflows (CAN-2004-0989)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040650004" comment="libxml-devel is earlier than 1:1.8.17-9.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040650005" comment="libxml-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040650002" comment="libxml is earlier than 1:1.8.17-9.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040650003" comment="libxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040651" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:651: imlib security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:651-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-651.html" />
          <reference source="CVE" ref_id="CVE-2004-1025" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1025.html" />
          <reference source="CVE" ref_id="CVE-2004-1026" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1026.html" />
    
    <description>The imlib packages contain an image loading and rendering library.

Pavel Kankovsky discovered several heap overflow flaws that were found in
the imlib image handler. An attacker could create a carefully crafted image
file in such a way that it could cause an application linked with imlib to
execute arbitrary code when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1025 to this issue.

Additionally, Pavel discovered several integer overflow flaws that were
found in the imlib image handler. An attacker could create a carefully
crafted image file in such a way that it could cause an application linked
with imlib to execute arbitrary code or crash when the file was opened by a
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1026 to this issue.

Users of imlib should update to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1025.html">CVE-2004-1025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1026.html">CVE-2004-1026</cve>
                <bugzilla href="http://bugzilla.redhat.com/138516" id="138516">CAN-2004-1025 Multiple imlib issues. (CAN-2004-1026)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651006" comment="imlib-cfgeditor is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465007" comment="imlib-cfgeditor is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651002" comment="imlib is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465003" comment="imlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651004" comment="imlib-devel is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465005" comment="imlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040654" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:654: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:654-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-654.html" />
          <reference source="CVE" ref_id="CVE-2004-1036" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1036.html" />
    
    <description>SquirrelMail is a webmail package written in PHP.

A cross-site scripting bug has been found in SquirrelMail.  This issue
could allow an attacker to send a mail with a carefully crafted header,
which could result in causing the victim's machine to execute a malicious
script. The Common Vulnerabilities and Exposures project has assigned the
name CAN-2004-1036 to this issue.

Additionally, the following issues have been addressed:

- updated splash screens
- HIGASHIYAMA Masato's patch to improve Japanese support
- real 1.4.3a tarball
- config_local.php and default_pref in /etc/squirrelmail/ to match upstream   
  RPM.

Please note that it is possible that upgrading to this package may remove
your SquirrelMail configuration files due to a bug in the RPM package. 
Upgrading will prevent this from happening in the future.

Users of SquirrelMail are advised to upgrade to this updated package which
contains a patched version of SquirrelMail version 1.43a and is not
vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1036.html">CVE-2004-1036</cve>
                <bugzilla href="http://bugzilla.redhat.com/112769" id="112769">The login page says Red Hat Linux instead of Fedora/RHEL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125638" id="125638">config_local.php is not listed as a config file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139739" id="139739">CAN-2004-1036 Cross Site Scripting in encoded text</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040654002" comment="squirrelmail is earlier than 0:1.4.3a-7.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040670" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:670: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:670-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-670.html" />
          <reference source="CVE" ref_id="CVE-2004-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1154.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

Greg MacManus of iDEFENSE Labs has discovered an integer overflow bug in
Samba versions prior to 3.0.10.  An authenticated remote user could exploit
this bug which may lead to arbitrary code execution on the Samba server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1154 to this issue.

Users of Samba should upgrade to these updated packages, which contain
backported security patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2004-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1154.html">CVE-2004-1154</cve>
                <bugzilla href="http://bugzilla.redhat.com/142472" id="142472">CAN-2004-1154 Samba authenticated remote root</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670004" comment="samba-client is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670006" comment="samba-common is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670002" comment="samba is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670008" comment="samba-swat is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040687" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:687: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:687-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-687.html" />
          <reference source="CVE" ref_id="CVE-2004-0958" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0958.html" />
          <reference source="CVE" ref_id="CVE-2004-0959" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0959.html" />
          <reference source="CVE" ref_id="CVE-2004-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1018.html" />
          <reference source="CVE" ref_id="CVE-2004-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1019.html" />
          <reference source="CVE" ref_id="CVE-2004-1065" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1065.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP.  PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow.  An attacker could create a carefully crafted image file in such
a way that if parsed by a PHP script using the exif extension it could
cause a crash or potentially execute arbitrary code.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

An information disclosure bug was discovered in the parsing of "GPC"
variables in PHP (query strings or cookies, and POST form data).  If
particular scripts used the values of the GPC variables, portions of the
memory space of an httpd child process could be revealed to the client. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0958 to this issue.

A file access bug was discovered in the parsing of "multipart/form-data"
forms, used by PHP scripts which allow file uploads.  In particular
configurations, some scripts could allow a malicious client to upload files
to an arbitrary directory where the "apache" user has write access.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0959 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions.  These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Various issues were discovered in the use of the "select" system call in
PHP, which could be triggered if PHP is used in an Apache configuration
where the number of open files (such as virtual host log files) exceeds the
default process limit of 1024.  Workarounds are now included for some of
these issues.

The "phpize" shell script included in PHP can be used to build third-party
extension modules.  A build issue was discovered in the "phpize" script on
some 64-bit platforms which prevented correct operation.

The "pcntl" extension module is now enabled in the command line PHP
interpreter, /usr/bin/php.  This module enables process control features 
such as "fork" and "kill" from PHP scripts.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-21" />
        <updated date="2004-12-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0958.html">CVE-2004-0958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0959.html">CVE-2004-0959</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1018.html">CVE-2004-1018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1019.html">CVE-2004-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1065.html">CVE-2004-1065</cve>
                <bugzilla href="http://bugzilla.redhat.com/131412" id="131412">Include process control extension, pcntl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131562" id="131562">phpize is broken on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132003" id="132003">fopen doesn't work across remote connections while under Apache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134971" id="134971">CAN-2004-0958 PHP variable parsing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134975" id="134975">CAN-2004-0959 PHP arbitrary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141132" id="141132">CAN-2004-1019 information disclosure issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142056" id="142056">CAN-2004-1065 ext/exif/exif.c - exif_read_data() overflow on long sectionname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687014" comment="php-odbc is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687010" comment="php-mysql is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687002" comment="php is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687012" comment="php-pgsql is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687004" comment="php-devel is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687006" comment="php-imap is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687008" comment="php-ldap is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040689" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:689: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:689-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-689.html" />
          <reference source="CVE" ref_id="CVE-2004-0565" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0565.html" />
          <reference source="CVE" ref_id="CVE-2004-1016" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1016.html" />
          <reference source="CVE" ref_id="CVE-2004-1017" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1017.html" />
          <reference source="CVE" ref_id="CVE-2004-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1137.html" />
          <reference source="CVE" ref_id="CVE-2004-1144" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1144.html" />
          <reference source="CVE" ref_id="CVE-2004-1234" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1234.html" />
          <reference source="CVE" ref_id="CVE-2004-1335" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1335.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

Petr Vandrovec discovered a flaw in the 32bit emulation code affecting the
Linux 2.4 kernel on the AMD64 architecture.  A local attacker could use
this flaw to gain privileges. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1144 to this issue.

ISEC security research discovered multiple vulnerabilities in the IGMP
functionality which was backported in the Red Hat Enterprise Linux 3
kernels.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

ISEC security research and Georgi Guninski independantly discovered a flaw
in the scm_send function in the auxiliary message layer.  A local user
could create a carefully crafted auxiliary message which could cause a
denial of service (system hang).  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1016 to this issue.

A floating point information leak was discovered in the ia64 architecture
context switch code.  A local user could use this flaw to read register
values of other processes by setting the MFH bit. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CAN-2004-0565 to this issue.

Kirill Korotaev found a flaw in load_elf_binary affecting kernels prior to
2.4.26.  A local user could create a carefully crafted binary in such a
way that it would cause a denial of service (system crash).  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CAN-2004-1234 to this issue.

These packages also fix issues in the io_edgeport driver, and a memory leak
in ip_options_get.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0565.html">CVE-2004-0565</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1016.html">CVE-2004-1016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1017.html">CVE-2004-1017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1137.html">CVE-2004-1137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1144.html">CVE-2004-1144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1234.html">CVE-2004-1234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1335.html">CVE-2004-1335</cve>
                <bugzilla href="http://bugzilla.redhat.com/124734" id="124734">CAN-2004-0565 Information leak on Linux/ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126126" id="126126">CAN-2004-0565 Information leak on Linux/ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142729" id="142729">CAN-2004-1016 CMSG validation checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142748" id="142748">CAN-2004-1137 IGMP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142964" id="142964">CAN-2004-1144 x86-64 privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142965" id="142965">CAN-2004-1234 kernel denial of service vulnerability and exploit</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689014" comment="kernel-source is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689002" comment="kernel is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689016" comment="kernel-doc is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689008" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689012" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689018" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689004" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689010" comment="kernel-smp is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050009" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:009: kdelibs, kdebase security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-009.html" />
          <reference source="CVE" ref_id="CVE-2004-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1158.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
          <reference source="CVE" ref_id="CVE-2005-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0078.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.

Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1158
to this issue.

A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-0078 to this issue.

All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1158.html">CVE-2004-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0078.html">CVE-2005-0078</cve>
                <bugzilla href="http://bugzilla.redhat.com/142393" id="142393">CAN-2004-1158 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145381" id="145381">CAN-2005-0078 password bypass in kde screensaver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146760" id="146760">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009002" comment="kdelibs is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009004" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009006" comment="kdebase is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009008" comment="kdebase-devel is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050010" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:010: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:010-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-010.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  It is possible
that a malicious user could create a file containing a specially crafted
modeline which could cause arbitrary command execution when viewed by a
victim.  Please note that this issue only affects users who have modelines
and filetype plugins enabled, which is not the default.  The  Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1138
to this issue.

All users of VIM are advised to upgrade to these erratum packages,
which contain a backported patch for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-05" />
        <updated date="2005-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
                <bugzilla href="http://bugzilla.redhat.com/142444" id="142444">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010002" comment="vim is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010004" comment="vim-common is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050011" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:011: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-011.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-02" />
        <updated date="2005-02-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/142952" id="142952">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145481" id="145481">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011002" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050012" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:012: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:012-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-012.html" />
          <reference source="CVE" ref_id="CVE-2004-0971" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0971.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

Additionally a temporary file bug was found in the Kerberos krb5-send-pr
program.  It is possible that an attacker could create a temporary file
that would allow an arbitrary file to be overwritten which the victim has
write access to.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0971 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-19" />
        <updated date="2005-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0971.html">CVE-2004-0971</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/136304" id="136304">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140066" id="140066">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142902" id="142902">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012006" comment="krb5-libs is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012004" comment="krb5-devel is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012008" comment="krb5-server is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012002" comment="krb5 is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012010" comment="krb5-workstation is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050013" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:013: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-013.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package.  An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.

A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.

The lppasswd utility ignores write errors when modifying the CUPS passwd
file.  A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.

In addition to these security issues, two other problems not relating
to security have been fixed:

Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop.  This has been fixed in later
versions of CUPS, and has been backported in these updated packages.

The cancel-cups(1) man page is a symbolic link to another man page.  The
target of this link has been corrected.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
                <bugzilla href="http://bugzilla.redhat.com/136973" id="136973">cancel-cups man page missing from errata package</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143087" id="143087">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143566" id="143566">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013004" comment="cups-devel is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013006" comment="cups-libs is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013002" comment="cups is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050018" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:018: xpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-018.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf packages should upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/143499" id="143499">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018002" comment="xpdf is earlier than 1:2.02-9.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050019" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:019: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-019.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

iDEFENSE has reported an integer overflow bug that affects libtiff. An
attacker who has the ability to trick a user into opening a malicious TIFF
file could cause the application linked to libtiff to crash or possibly
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin reported another integer overflow in the tiffdump 
utility.  An atacker who has the ability to trick a user into opening a
malicious TIFF file with tiffdump could possibly execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/143505" id="143505">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143577" id="143577">CVE-2004-1183 libtiff: tiffdump integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019002" comment="libtiff is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019004" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050021" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:021: kdegraphics security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:021-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-021.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1307.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
    
    <description>The kdegraphics package contains graphics applications for the K Desktop
Environment.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. The kfax application contains a copy of
the libtiff code used for parsing TIFF files and is therefore affected by
these bugs. An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause kfax to crash or possibly execute arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found. The kfax application contains a copy of the libtiff code used
for parsing TIFF files and is therefore affected by these bugs. An attacker
who has the ability to trick a user into opening a malicious TIFF file
could cause kfax to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0803 to this issue.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-14" />
        <updated date="2005-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1307.html">CVE-2004-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
                <bugzilla href="http://bugzilla.redhat.com/135466" id="135466">CAN-2004-0803 buffer overflows in libtiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135470" id="135470">CAN-2004-0886 multiple integer overflows in libtiff</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021002" comment="kdegraphics is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021004" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050025" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:025: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-025.html" />
          <reference source="CVE" ref_id="CVE-2005-0021" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0021.html" />
          <reference source="CVE" ref_id="CVE-2005-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0022.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. 

A buffer overflow was discovered in the spa_base64_to_bits function in
Exim, as originally obtained from Samba code.  If SPA authentication is
enabled, a remote attacker may be able to exploit this vulnerability to
execute arbitrary code as the 'exim' user.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to
this issue.  Please note that SPA authentication is not enabled by default
in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and
dns_build_reverse functions in Exim.  A local user can trigger these flaws
by executing exim with carefully crafted command line arguments and may be
able to gain the privileges of the 'exim' account.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0021.html">CVE-2005-0021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0022.html">CVE-2005-0022</cve>
                <bugzilla href="http://bugzilla.redhat.com/144099" id="144099">CAN-2005-0021 exim security issues (CAN-2005-0022)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025002" comment="exim is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050026" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:026: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:026-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-026.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/144257" id="144257">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145055" id="145055">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026006" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026002" comment="tetex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026012" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026014" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026004" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026008" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026010" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050032" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:032: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:032-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-032.html" />
          <reference source="CVE" ref_id="CVE-2004-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1018.html" />
          <reference source="CVE" ref_id="CVE-2004-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1019.html" />
          <reference source="CVE" ref_id="CVE-2004-1065" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1065.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP. PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow. An attacker could create a carefully crafted image file in such
a way which, if parsed by a PHP script using the exif extension, could
cause a crash or potentially execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions. These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1018.html">CVE-2004-1018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1019.html">CVE-2004-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1065.html">CVE-2004-1065</cve>
                <bugzilla href="http://bugzilla.redhat.com/141136" id="141136">CAN-2004-1018 Multiple issues in PHP (CAN-2004-1019 CAN-2004-1020)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032028" comment="php-gd is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032016" comment="php-odbc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032012" comment="php-mysql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032002" comment="php is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032022" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032024" comment="php-mbstring is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032014" comment="php-pgsql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032004" comment="php-devel is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032026" comment="php-ncurses is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032018" comment="php-snmp is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032008" comment="php-imap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032006" comment="php-pear is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032020" comment="php-domxml is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032010" comment="php-ldap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050033" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:033: alsa-lib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-033.html" />
          <reference source="CVE" ref_id="CVE-2005-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0087.html" />
    
    <description>The alsa-lib package provides a library of functions for communication with
kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack
execution protection to be disabled for the libasound.so library.  
The effect of this flaw is that stack execution protection, through NX or
Exec-Shield, would be disabled for any application linked to libasound. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a
patched version of the library which correctly enables stack execution
protection.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0087.html">CVE-2005-0087</cve>
                <bugzilla href="http://bugzilla.redhat.com/144518" id="144518">CAN-2005-0087 alsa-lib disables stack protection for it's users</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033004" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033005" comment="alsa-lib-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033002" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033003" comment="alsa-lib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050034" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:034: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:034-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-034.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf. An attacker could construct a carefully crafted PDF file that could
cause Xpdf to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org).  Red Hat Enterprise Linux 4 contained a fix for this
issue, but it was found to be incomplete and left 64-bit architectures
vulnerable.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0206 to this issue.

All users of Xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135066" id="135066">PDF is displayed garbled, older xpdf works</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144197" id="144197">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145052" id="145052">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147498" id="147498">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050034002" comment="xpdf is earlier than 1:3.00-11.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050035" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:035: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:035-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-035.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

infamous41md discovered integer overflow flaws in libtiff.  An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to overflow a heap buffer when the
file was opened by a victim.  Due to the nature of the overflow it is
unlikely that it is possible to use this flaw to execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin discovered an integer overflow flaw in libtiff.  An
attacker could create a carefully crafted TIFF file in such a way that it
could cause an application linked with libtiff to crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/144185" id="144185">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144186" id="144186">CAN-2004-1183 libtiff integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035002" comment="libtiff is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035004" comment="libtiff-devel is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050036" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:036: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-036.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  An attacker
could create a text file containing a specially crafted modeline which
could cause arbitrary command execution when viewed by a victim using VIM. 
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-1138 to this issue.  Please note that this issue only affects
users who have modelines and filetype plugins enabled, which is not the
default.  

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM.  A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue. 

All users of VIM are advised to upgrade to these erratum packages,
which contain backported patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144187" id="144187">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144880" id="144880">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036006" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036002" comment="vim is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036010" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036004" comment="vim-common is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036008" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050037" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:037: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-037.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization.  (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084) 

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/144188" id="144188">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145483" id="145483">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037002" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050038" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:038: mozilla security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:038-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-038.html" />
          <reference source="CVE" ref_id="CVE-2004-1316" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1316.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way
Mozilla handles NNTP URLs.  If a user visits a malicious web page or is
convinced to click on a malicious link, it may be possible for an attacker
to execute arbitrary code on the victim's machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1316.html">CVE-2004-1316</cve>
                <bugzilla href="http://bugzilla.redhat.com/143994" id="143994">CAN-2004-1316 buffer overflow in mozilla</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038002" comment="mozilla is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050039" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:039: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-039.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences. A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document. An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments. These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144683" id="144683">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039002" comment="enscript is earlier than 0:1.6.1-24.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050040" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:040: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:040-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-040.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences.  A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document.  An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments.  These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144686" id="144686">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050040002" comment="enscript is earlier than 0:1.6.1-28.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050043" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:043: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:043-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-043.html" />
          <reference source="CVE" ref_id="CVE-2004-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0791.html" />
          <reference source="CVE" ref_id="CVE-2004-1074" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1074.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2004-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1237.html" />
          <reference source="CVE" ref_id="CVE-2005-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0003.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1235 to
this issue.

A flaw was discovered where an executable could cause a VMA overlap leading
to a crash.  A local user could trigger this flaw by creating a carefully
crafted a.out binary on 32-bit systems or a carefully crafted ELF binary
on Itanium systems.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0003 to this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0001 to this issue. A patch
that coincidentally fixed this issue was committed to the Update 4 kernel
release in December 2004.  Therefore Red Hat Enterprise Linux 3 kernels
provided by RHBA-2004:550 and subsequent updates are not vulnerable to
this issue.

A flaw in the system call filtering code in the audit subsystem included
in Red Hat Enterprise Linux 3 allowed a local user to cause a crash when
auditing was enabled.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1237 to this issue.

Olaf Kirch discovered that the recent security fixes for cmsg_len handling
(CAN-2004-1016) broke 32-bit compatibility on 64-bit platforms such as
AMD64 and Intel EM64T. A patch to correct this issue is included.

A recent Internet Draft by Fernando Gont recommended that ICMP Source
Quench messages be ignored by hosts.  A patch to ignore these messages is
included.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-18" />
        <updated date="2005-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0791.html">CVE-2004-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1074.html">CVE-2004-1074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1237.html">CVE-2004-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0003.html">CVE-2005-0003</cve>
                <bugzilla href="http://bugzilla.redhat.com/132245" id="132245">CAN-2004-1237 Kernel panic when stopping Lotus Domino 6.52</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141996" id="141996">CAN-2004-1237 instant kernel panic from one line perl program - BAD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142091" id="142091">CAN-2004-1237 kernel oops captured, system hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142442" id="142442">CAN-2004-1237 kernel panic ( __audit_get_target)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143866" id="143866">CAN-2004-1237 kernel panic caused by auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144048" id="144048">CAN-2004-1237 kernel panic when Oracle agentctl is run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144134" id="144134">CAN-2004-1235 isec.pl uselib() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144784" id="144784">CAN-2005-0003 huge vma-in-executable bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043004" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043002" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043006" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043018" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043014" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043012" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050045" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:045: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-045.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/144196" id="144196">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045006" comment="krb5-libs is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045004" comment="krb5-devel is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045008" comment="krb5-server is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045002" comment="krb5 is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045010" comment="krb5-workstation is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050049" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:049: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:049-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-049.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit these buffer overflow
vulnerabilities on x86 architectures.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145102" id="145102">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049004" comment="cups-devel is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049006" comment="cups-libs is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049002" comment="cups is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050053" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:053: CUPS security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:053-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-053.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects CUPS due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause CUPS to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects the CUPS pdftops filter due to a shared codebase.  An attacker
who has the ability to send a malicious PDF file to a printer could
possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the ParseCommand function in the
hpgltops program. An attacker who has the ability to send a malicious HPGL
file to a printer could possibly execute arbitrary code as the "lp" user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1267 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

The lppasswd utility was found to ignore write errors when modifying the
CUPS passwd file. A local user who is able to fill the associated file
system could corrupt the CUPS password file or prevent future uses of
lppasswd. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility was found to not verify that the passwd.new file is
different from STDERR, which could allow local users to control output to
passwd.new via certain user input that triggers an error message. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1270 to this issue.

All users of cups should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144191" id="144191">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144194" id="144194">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145088" id="145088">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147480" id="147480">CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053002" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050057" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:057: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:057-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-057.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files for GNOME. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

Users should update to this erratum package which contains backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144210" id="144210">CAN-2004-1125 gpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145054" id="145054">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147518" id="147518">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057002" comment="gpdf is earlier than 0:2.8.2-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050059" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:059: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-059.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found when processing the /Encrypt /Length tag.
An attacker could construct a carefully crafted PDF file that could cause
Xpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf package should upgrade to this updated package,
which resolves this issue</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145049" id="145049">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050059002" comment="xpdf is earlier than 1:2.02-9.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050060" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:060: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-060.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious webpage
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious Web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious Web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145545" id="145545">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146161" id="146161">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146779" id="146779">CAN-2005-0211 Buffer overflow in WCCP recvfrom() call</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146785" id="146785">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050061" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:061: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:061-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-061.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious web page
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-11" />
        <updated date="2005-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145540" id="145540">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146159" id="146159">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146780" id="146780">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050061002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050065" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:065: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:065-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-065.html" />
          <reference source="CVE" ref_id="CVE-2004-1145" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1145.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in
the Konqueror web browser. If a user has Java enabled in Konqueror and
visits a malicious website, the website could run a carefully crafted
Java-applet and obtain escalated privileges allowing reading and writing of
arbitrary files with the privileges of the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave.  KDE applications such as
Konqueror could be forced to execute arbitrary FTP commands via a carefully
crafted ftp URL.  The URL could also be crafted in such a way as to send an
arbitrary email via SMTP.  An attacker could make use of this flaw if a
victim visits a malicious web site. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1145.html">CVE-2004-1145</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
                <bugzilla href="http://bugzilla.redhat.com/144211" id="144211">CAN-2004-1145 Konqueror Java Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145938" id="145938">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065002" comment="kdelibs is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065004" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050066" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:066: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-066.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that
also affects kpdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects kpdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf which also affects
kpdf due to a shared codebase. An attacker could construct a carefully
crafted PDF file that could cause kpdf to crash or possibly execute
arbitrary code when opened. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/144231" id="144231">CAN-2004-1125 kpdf buffer overflows (CAN-2005-0064)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147517" id="147517">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066002" comment="kdegraphics is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050068" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:068: less security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:068-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-068.html" />
          <reference source="CVE" ref_id="CVE-2005-0086" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0086.html" />
    
    <description>The less utility is a text file browser that resembles more, but has
extended capabilities.

Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue.  Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit this vulnerability on x86
architectures.

All users of the less package should upgrade to this updated package,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0086.html">CVE-2005-0086</cve>
                <bugzilla href="http://bugzilla.redhat.com/145527" id="145527">CAN-2005-0086 less crashes on scrolling of binary files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068002" comment="less is earlier than 0:378-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068003" comment="less is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050069" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:069: perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:069-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-069.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069002" comment="perl-DBI is earlier than 0:1.32-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050070" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:070: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:070-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-070.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
          <reference source="CVE" ref_id="CVE-2005-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0759.html" />
          <reference source="CVE" ref_id="CVE-2005-0760" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0760.html" />
          <reference source="CVE" ref_id="CVE-2005-0761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0761.html" />
          <reference source="CVE" ref_id="CVE-2005-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0762.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible
that a TIFF image file with an invalid tag could cause ImageMagick to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a
specially crafted TIFF image file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible
that a specially crafted PSD file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser.  It is possible
that an attacker could execute arbitrary code by tricking a user into
opening a specially crafted SGI image file. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0759.html">CVE-2005-0759</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0760.html">CVE-2005-0760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0761.html">CVE-2005-0761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0762.html">CVE-2005-0762</cve>
                <bugzilla href="http://bugzilla.redhat.com/145111" id="145111">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150312" id="150312">CAN-2005-0759 Denial of Service in .tiff images with invalid TAG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150315" id="150315">CAN-2005-0760 Accessing memory outside of image during decoding of TIFF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150323" id="150323">CAN-2005-0761 Bug in parsing PSD files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150327" id="150327">CAN-2005-0762 Buffer overflow in SGI parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070004" comment="ImageMagick-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070006" comment="ImageMagick-perl is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070002" comment="ImageMagick is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070008" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050071" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:071: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:071-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-071.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/145123" id="145123">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071002" comment="ImageMagick is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050072" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:072: perl-DBI security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:072-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-072.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050072002" comment="perl-DBI is earlier than 0:1.40-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050073" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:073: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:073-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-073.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive.  

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option.  This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

Users of cpio should upgrade to this updated package, which resolves
this issue.

Red Hat would like to thank Mike O'Connor for bringing this issue to our
attention.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/145725" id="145725">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073002" comment="cpio is earlier than 0:2.5-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050074" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:074: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:074-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-074.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory.  This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rexec command failed with "Invalid Argument", because the code
used sigaction() as an unsupported signal.

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

The rexec command prompted for username and password regardless of the
~/.netrc configuration file contents. This updated package contains a patch
that no longer skips the ~/.netrc file. 

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/67361" id="67361">rcp gives incorrect error report when file system writes fai</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118630" id="118630">rexec fails with "Invalid Argument"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146435" id="146435">RHEL3: rexec prompts for username/password before checking ~/.netrc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146437" id="146437">RHEL3: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146464" id="146464">malicious rsh server can cause rcp to write to arbitrary files (like scp CAN-2004-0175)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074002" comment="rsh is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074004" comment="rsh-server is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050080" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:080: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:080-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-080.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option. This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

All users of cpio should upgrade to this updated package, which resolves
this issue, and adds support for large files (> 2GB).</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145720" id="145720">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050080002" comment="cpio is earlier than 0:2.5-3e.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050081" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:081: ghostscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:081-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-081.html" />
          <reference source="CVE" ref_id="CVE-2004-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0967.html" />
    
    <description>Ghostscript is a program for displaying PostScript files or printing them
to non-PostScript printers.

A bug was found in the way several of Ghostscript's utility scripts created
temporary files. A local user could cause these utilities to overwrite
files that the victim running the utility has write access to.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2004-0967 to
this issue.

Additionally, this update addresses the following issue:

A problem has been identified in the PDF output driver, which can cause
output to be delayed indefinitely on some systems.  The fix has been
backported from GhostScript 7.07.

All users of ghostscript should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0967.html">CVE-2004-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/97583" id="97583">[7.05-20.1] gs gets stuck reading /dev/random</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136321" id="136321">CAN-2004-0967 temporary file vulnerabilities in various ghostscript scripts.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081002" comment="ghostscript is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081003" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081004" comment="ghostscript-devel is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081005" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081006" comment="hpijs is earlier than 0:1.3-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081007" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050090" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:090: htdig security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-090.html" />
          <reference source="CVE" ref_id="CVE-2005-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0085.html" />
    
    <description>The ht://Dig system is a Web search and indexing system for a small domain
or intranet.

Michael Krax reported a cross-site scripting bug affecting htdig. An
attacker could construct a carefully crafted URL which can cause a web
browser to execute malicious script once visited.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-0085
to this issue.

Users of htdig should upgrade to these updated packages, which contain a
backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0085.html">CVE-2005-0085</cve>
                <bugzilla href="http://bugzilla.redhat.com/144261" id="144261">CAN-2005-0085 XSS vulnerability in htdig 3.2.0b6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145649" id="145649">htdig packaging cleanups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090002" comment="htdig is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090003" comment="htdig is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090004" comment="htdig-web is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090005" comment="htdig-web is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050092" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:092: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:092-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-092.html" />
          <reference source="CVE" ref_id="CVE-2004-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1056.html" />
          <reference source="CVE" ref_id="CVE-2004-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1137.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2005-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0001.html" />
          <reference source="CVE" ref_id="CVE-2005-0090" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0090.html" />
          <reference source="CVE" ref_id="CVE-2005-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0091.html" />
          <reference source="CVE" ref_id="CVE-2005-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0092.html" />
          <reference source="CVE" ref_id="CVE-2005-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0176.html" />
          <reference source="CVE" ref_id="CVE-2005-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0177.html" />
          <reference source="CVE" ref_id="CVE-2005-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0178.html" />
          <reference source="CVE" ref_id="CVE-2005-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0179.html" />
          <reference source="CVE" ref_id="CVE-2005-0180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0180.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered multiple vulnerabilities in the IGMP
functionality.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  (CAN-2005-0001)

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  (CAN-2004-1235)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architecture was discovered.  A local user could use this flaw to write to
privileged IO ports.  (CAN-2005-0204)

The Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not
properly check the DMA lock, which could allow remote attackers or local
users to cause a denial of service (X Server crash) or possibly modify the
video output. (CAN-2004-1056)

OGAWA Hirofumi discovered incorrect tables sizes being used in the
filesystem Native Language Support ASCII translation table.  This could
lead to a denial of service (system crash).  (CAN-2005-0177)

Michael Kerrisk discovered a flaw in the 2.6.9 kernel which allows users to
unlock arbitrary shared memory segments.  This flaw could lead to
applications not behaving as expected.  (CAN-2005-0176)

Improvements in the POSIX signal and tty standards compliance exposed
a race condition.  This flaw can be triggered accidentally by threaded
applications or deliberately by a malicious user and can result in a
denial of service (crash) or in occasional cases give access to a small
random chunk of kernel memory.  (CAN-2005-0178)

The PaX team discovered a flaw in mlockall introduced in the 2.6.9 kernel.
An unprivileged user could use this flaw to cause a denial of service
(CPU and memory consumption or crash).  (CAN-2005-0179)

Brad Spengler discovered multiple flaws in sg_scsi_ioctl in the 2.6 kernel.
An unprivileged user may be able to use this flaw to cause a denial of
service (crash) or possibly other actions.  (CAN-2005-0180)

Kirill Korotaev discovered a missing access check regression in the Red Hat
Enterprise Linux 4 kernel 4GB/4GB split patch.  On systems using the
hugemem kernel, a local unprivileged user could use this flaw to cause a
denial of service (crash).  (CAN-2005-0090)

A flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch can
allow syscalls to read and write arbitrary kernel memory.  On systems using
the hugemem kernel, a local unprivileged user could use this flaw to gain
privileges.  (CAN-2005-0091)

An additional flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split
patch was discovered. On x86 systems using the hugemem kernel, a local
unprivileged user may be able to use this flaw to cause a denial of service
(crash).  (CAN-2005-0092)

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1056.html">CVE-2004-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1137.html">CVE-2004-1137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0001.html">CVE-2005-0001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0090.html">CVE-2005-0090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0091.html">CVE-2005-0091</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0092.html">CVE-2005-0092</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0176.html">CVE-2005-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0177.html">CVE-2005-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0178.html">CVE-2005-0178</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0179.html">CVE-2005-0179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0180.html">CVE-2005-0180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
                <bugzilla href="http://bugzilla.redhat.com/142670" id="142670">CAN-2004-1137 IGMP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144131" id="144131">CAN-2005-0090 4GB split DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144136" id="144136">CAN-2004-1235 isec.pl do_brk() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144391" id="144391">CAN-2004-1056 insufficient locking checks in DRM code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144412" id="144412">CAN-2005-0001 page fault @ SMP privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144471" id="144471">CAN-2005-0176 unlock someone elses ipc memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144522" id="144522">CAN-2005-0180 2.6 scsi ioctl integer overflow and information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144528" id="144528">CAN-2005-0179 RLIMIT_MEMLOCK bypass and (2.6) unprivileged user DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144532" id="144532">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144658" id="144658">CAN-2005-0091 4g4g PROT_NONE fix (CAN-2005-0092)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146083" id="146083">20041212 Clear ebp on sysenter return</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146095" id="146095">CAN-2005-0177 nls_ascii incorrect table size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146101" id="146101">CAN-2005-0178 tty/setsid race</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092002" comment="kernel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092006" comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092004" comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092008" comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050094" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:094: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:094-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-094.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
    
    <description>Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victim's
clipboard. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0146 to this issue.

A bug was found in the way Thunderbird handled cookies when loading content
over HTTP regardless of the user's preference. It is possible that a
particular user could be tracked through the use of malicious mail messages
which load content over HTTP. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0149 to this issue.

Users of Thunderbird are advised to upgrade to this updated package,
which contains Thunderbird version 1.0 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
                <bugzilla href="http://bugzilla.redhat.com/146315" id="146315">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156749" id="156749">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094002" comment="thunderbird is earlier than 0:1.0-1.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050099" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:099: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:099-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-099.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145387" id="145387">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145967" id="145967">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050100" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:100: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-100.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146657" id="146657">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050100002" comment="mod_python is earlier than 0:3.1.3-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050102" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:102: dbus security update. (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-102.html" />
          <reference source="CVE" ref_id="CVE-2005-0201" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0201.html" />
    
    <description>D-BUS is a system for sending messages between applications. It is
used both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Dan Reed discovered that a user can send and listen to messages on another
user's per-user session bus if they know the address of the socket. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0201 to this issue.  In Red Hat Enterprise Linux 4, the
per-user session bus is only used for printing notifications,  therefore
this issue would only allow a local user to examine or send additional
print notification messages.

Users of dbus are advised to upgrade to these updated packages,
which contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0201.html">CVE-2005-0201</cve>
                <bugzilla href="http://bugzilla.redhat.com/146766" id="146766">CAN-2005-0201 dbus information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102008" comment="dbus-x11 is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102009" comment="dbus-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102010" comment="dbus-python is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102011" comment="dbus-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102004" comment="dbus-devel is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102005" comment="dbus-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102002" comment="dbus is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102003" comment="dbus is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102006" comment="dbus-glib is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102007" comment="dbus-glib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050103" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:103: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-103.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

An unsafe file permission bug was discovered in the rmtree() function in
the File::Path module.  The rmtree() function removes files and directories
in an insecure manner, which could allow a local user to read or delete
arbitrary files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0452 to this issue.

Users of Perl are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/146739" id="146739">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156 )</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146774" id="146774">CAN-2004-0452 File::Path::rmtree() issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103004" comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103002" comment="perl is earlier than 3:5.8.5-12.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050104" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:104: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-104.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146655" id="146655">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050104002" comment="mod_python is earlier than 0:3.0.3-5.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050105" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:105: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-105.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-07" />
        <updated date="2005-02-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/140227" id="140227">Potential insecurity in CGI.pm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146737" id="146737">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105006" comment="perl-CGI is earlier than 2:2.81-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105008" comment="perl-DB_File is earlier than 2:1.804-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105010" comment="perl-suidperl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105004" comment="perl-CPAN is earlier than 2:1.61-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105002" comment="perl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050106" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:106: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-106.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH
replaces rlogin and rsh, and provides secure encrypted communications
between two untrusted hosts over an insecure network. X11 connections and
arbitrary TCP/IP ports can also be forwarded over a secure channel. Public
key authentication can be used for "passwordless" access to servers.

The scp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses scp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also correct the following bugs:

On systems where direct ssh access for the root user was disabled by
configuration (setting "PermitRootLogin no"), attempts to guess the root
password could be judged as sucessful or unsucessful by observing a delay.

On systems where the privilege separation feature was turned on, the user
resource limits were not correctly set if the configuration specified to
raise them above the defaults.  It was also not possible to change an
expired password.

Users of openssh should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/120147" id="120147">CAN-2004-0175 malicious ssh server can cause scp to write to arbitrary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124602" id="124602">OpenSSH does not allow users to change expired passwords when privsep is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141642" id="141642">SSH allows attacker to divine root password</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106002" comment="openssh is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050108" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:108: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:108-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-108.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146649" id="146649">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108004" comment="python-devel is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108008" comment="python-docs is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108010" comment="tkinter is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108002" comment="python is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108006" comment="python-tools is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050109" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:109: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-109.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146645" id="146645">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109004" comment="python-devel is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109008" comment="python-docs is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109010" comment="tkinter is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109002" comment="python is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109006" comment="python-tools is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050110" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:110: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-110.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running emacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146702" id="146702">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110008" comment="emacs-el is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110010" comment="emacs-leim is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110002" comment="emacs is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110006" comment="emacs-common is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110007" comment="emacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110004" comment="emacs-nox is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110005" comment="emacs-nox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050112" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:112: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:112-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-112.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running emacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146700" id="146700">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112004" comment="emacs-el is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112006" comment="emacs-leim is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112002" comment="emacs is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050122" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:122: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:122-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-122.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM. A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue.

All users of VIM are advised to upgrade to these erratum packages, which
contain a backported patche for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144695" id="144695">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122002" comment="vim is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122004" comment="vim-common is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050128" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:128: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:128-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-128.html" />
          <reference source="CVE" ref_id="CVE-2005-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0198.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access
protocols.

A logic error in the CRAM-MD5 code in the University of Washington IMAP
(UW-IMAP) server was discovered.  When Challenge-Response Authentication
Mechanism with MD5 (CRAM-MD5) is enabled, UW-IMAP does not properly enforce
all the required conditions for successful authentication, which could
allow remote attackers to authenticate as arbitrary users.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
 CAN-2005-0198 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-23" />
        <updated date="2005-02-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0198.html">CVE-2005-0198</cve>
                <bugzilla href="http://bugzilla.redhat.com/145469" id="145469">CAN-2005-0198 user validation issue in imap when using CRAM-MD5 authetication</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128006" comment="imap-utils is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128004" comment="imap-devel is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128002" comment="imap is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050132" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:132: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-132.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect Xpdf.  CUPS contained a copy of the Xpdf code
used for parsing PDF files and was therefore affected by these bugs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2004-0888 to this issue, and Red Hat released erratum
RHSA-2004:543 with updated packages.

It was found that the patch used to correct this issue was not sufficient
and did not fully protect CUPS running on 64-bit architectures.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue. 

These updated packages also include a fix that prevents the CUPS
initscript from being accidentally replaced.

All users of CUPS on 64-bit architectures should upgrade to these updated
packages, which contain a corrected patch and are not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135378" id="135378">CAN-2004-0888 xpdf issues affect cups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132004" comment="cups-devel is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132006" comment="cups-libs is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132002" comment="cups is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050133" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:133: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:133-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-133.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running xemacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146706" id="146706">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133004" comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133005" comment="xemacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133010" comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133008" comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133006" comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133007" comment="xemacs-nox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133002" comment="xemacs is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050134" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:134: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:134-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-134.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running xemacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146704" id="146704">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134006" comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134004" comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134002" comment="xemacs is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050135" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:135: squirrelmail security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:135-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-135.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145384" id="145384">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145964" id="145964">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050135002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050136" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:136: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:136-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-136.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>The mailman package is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147342" id="147342">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136002" comment="mailman is earlier than 3:2.1.5-24.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050137" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:137: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:137-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-137.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>Mailman is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.  

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of Mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147344" id="147344">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050137002" comment="mailman is earlier than 3:2.1.5-31.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050138" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:138: postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:138-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-138.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>A flaw in the LOAD command in PostgreSQL was discovered. A local user
could use this flaw to load arbitrary shared libraries and therefore
execute arbitrary code, gaining the privileges of the PostgreSQL server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered. A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL. A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found. A user could create carefully crafted arrays and cause a denial of
service (crash). The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

The update also fixes some minor problems, notably conflicts with SELinux.

Users of postgresql should update to these erratum packages that contain
patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147380" id="147380">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138020" comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138008" comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138012" comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138022" comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138010" comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138004" comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138016" comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138002" comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138018" comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138014" comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138006" comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050141" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:141: rh-postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:141-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-141.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw in the LOAD command in PostgreSQL was discovered.  A local user
could use this flaw to load arbitrary shared librarys and therefore execute
arbitrary code, gaining the privileges of the PostgreSQL server.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered.  A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL.  A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found.  A user could create carefully crafted arrays and cause a denial of
service (crash).  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

Users of PostgreSQL are advised to update to these erratum packages which
are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147442" id="147442">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141020" comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141008" comment="rh-postgresql-docs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141010" comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141002" comment="rh-postgresql is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141018" comment="rh-postgresql-python is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141014" comment="rh-postgresql-pl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141012" comment="rh-postgresql-devel is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141022" comment="rh-postgresql-test is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141016" comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141006" comment="rh-postgresql-server is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141004" comment="rh-postgresql-libs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050152" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:152: postfix security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-152.html" />
          <reference source="CVE" ref_id="CVE-2005-0337" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0337.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the ipv6 patch used with Postfix.  When the file
/proc/net/if_inet6 is not available and permit_mx_backup is enabled in
smtpd_recipient_restrictions, this flaw could allow remote attackers to
bypass e-mail restrictions and perform mail relaying by sending mail to an
IPv6 hostname.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0337 to this issue.

These updated packages also fix the following problems:

- wrong permissions on doc directory
- segfault when gethostbyname or gethostbyaddr fails

All users of postfix should upgrade to these updated packages, which
contain patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0337.html">CVE-2005-0337</cve>
                <bugzilla href="http://bugzilla.redhat.com/139983" id="139983">newaliases segfaults when gethostbyname or gethostbyaddr fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146732" id="146732">CAN-2005-0337 open relay bug in postfix ipv6 patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147280" id="147280">Permissions on doc directory is wrong</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152004" comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152005" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152002" comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152003" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050165" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:165: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-165.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/146978" id="146978">RHEL4: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146979" id="146979">RHEL4: rcp gives incorrect error report when file system writes fai</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165002" comment="rsh is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165004" comment="rsh-server is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050173" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:173: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:173-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-173.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles FQDN lookups.  It was possible  
to crash the Squid server by sending a carefully crafted DNS response to  
an FQDN lookup.  The Common Vulnerabilities and Exposures project  
(cve.mitre.org) has assigned the name CAN-2005-0446 to this issue.  
  
Users of squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050173002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050175" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:175: kdenetwork security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:175-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-175.html" />
          <reference source="CVE" ref_id="CVE-2005-0205" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0205.html" />
    
    <description>The kdenetwork packages contain a collection of networking applications for
the K Desktop Environment.

A bug was found in the way kppp handles privileged file descriptors.  A
malicious local user could make use of this flaw to modify the /etc/hosts
or /etc/resolv.conf files, which could be used to spoof domain information. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0205 to this issue.

Please note that the default installation of kppp on Red Hat Enterprise
Linux uses consolehelper and is not vulnerable to this issue.  However, the
kppp FAQ provides instructions for removing consolehelper and running kppp
suid root, which is a vulnerable configuration.

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0205.html">CVE-2005-0205</cve>
                <bugzilla href="http://bugzilla.redhat.com/148912" id="148912">CAN-2005-0205 kppp local domain name hijacking</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175002" comment="kdenetwork is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175004" comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050176" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:176: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-176.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0589.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0592.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the Firefox string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

A bug was found in the way Firefox handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Firefox allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527).

A flaw was found in the way Firefox displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Firefox handles plug-in temporary files. A
malicious local user could create a symlink to a victims directory, causing
it to be deleted when the victim exits Firefox. (CAN-2005-0578)

A bug has been found in one of Firefox's UTF-8 converters. It may be
possible for an attacker to supply a specially crafted UTF-8 string to the
buggy converter, leading to arbitrary code execution. (CAN-2005-0592)

A bug was found in the Firefox javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Firefox displays the HTTP authentication prompt.
When a user is prompted for authentication, the dialog window is displayed
over the active tab, regardless of the tab that caused the pop-up to appear
and could trick a user into entering their username and password for a
trusted site.  (CAN-2005-0584)

A bug was found in the way Firefox displays the save file dialog. It is
possible for a malicious webserver to spoof the Content-Disposition header,
tricking the user into thinking they are downloading a different filetype.
(CAN-2005-0586)

A bug was found in the way Firefox handles users "down-arrow" through auto
completed choices. When an autocomplete choice is selected, the information
is copied into the input control, possibly allowing a malicious web site to
steal information by tricking a user into arrowing through autocompletion
choices. (CAN-2005-0589)

Several bugs were found in the way Firefox displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0593)

A bug was found in the way Firefox displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

A bug was found in the way Firefox handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

A bug was found in the way Firefox displays the installation confirmation
dialog. An attacker could add a long user:pass before the true hostname,
tricking a user into thinking they were installing content from a trusted
source. (CAN-2005-0590)

A bug was found in the way Firefox displays download and security dialogs.
An attacker could cover up part of a dialog window tricking the user into
clicking "Allow" or "Open", which could potentially lead to arbitrary code
execution. (CAN-2005-0591)

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-01" />
        <updated date="2005-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0589.html">CVE-2005-0589</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0592.html">CVE-2005-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/142506" id="142506">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144216" id="144216">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147402" id="147402">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147727" id="147727">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147735" id="147735">CAN-2005-0231 firefox javascript tab security bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149876" id="149876">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149923" id="149923">CAN-2005-0578 Unsafe /tmp/plugtmp directory exploitable to erase user's files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149929" id="149929">CAN-2005-0584 HTTP auth prompt tab spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149930" id="149930">CAN-2005-0586 Download dialog spoofing using Content-Disposition header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149931" id="149931">CAN-2005-0588 XSLT can include stylesheets from arbitrary hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149934" id="149934">CAN-2005-0589 Autocomplete data leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149936" id="149936">CAN-2005-0590 Install source spoofing with user:pass@host</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149937" id="149937">CAN-2005-0591 Spoofing download and security dialogs with overlapping windows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149938" id="149938">CAN-2005-0592 Heap overflow possible in UTF8 to Unicode conversion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149939" id="149939">CAN-2005-0593 SSL "secure site" indicator spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176002" comment="firefox is earlier than 0:1.0.1-1.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050198" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:198: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:198-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-198.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>X.Org X11 is the X Window System which provides the core functionality
of the Linux GUI desktop.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
carefully crafted XPM file in such a way that it could cause an application
linked with libXpm to execute arbitrary code when the file was opened by a
victim. The Common Vulnerabilities and Exposures project  (cve.mitre.org)
has assigned the name CAN-2005-0605 to this issue. 

Since the initial release of Red Hat Enterprise Linux 4, a number of issues
have been addressed in the X.Org X11 X Window System.  This erratum also
updates X11R6.8 to the latest stable point release (6.8.2), which includes
various stability and reliability fixes including (but not limited to) the
following:

- The 'radeon' driver has been modified to disable "RENDER" acceleration
  by default, due to a bug in the implementation which has not yet
  been isolated.  This can be manually re-enabled by using the
  following option in the device section of the X server config file:

    Option "RenderAccel"

- The 'vmware' video driver is now available on 64-bit AMD64 and
  compatible systems.

- The Intel 'i810' video driver is now available on 64-bit EM64T
  systems.

- Stability fixes in the X Server's PCI handling layer for 64-bit systems,
  which resolve some issues reported by "vesa" and "nv" driver users.

- Support for Hewlett Packard's Itanium ZX2 chipset.

- Nvidia "nv" video driver update provides support for some of
  the newer Nvidia chipsets, as well as many stability and reliability
  fixes.

- Intel i810 video driver stability update, which fixes the widely
  reported i810/i815 screen refresh issues many have experienced.

- Packaging fixes for multilib systems, which permit both 32-bit
  and 64-bit X11 development environments to be simultaneously installed
  without file conflicts.

In addition to the above highlights, the X.Org X11 6.8.2 release has a
large number of additional stability fixes which resolve various other
issues reported since the initial release of Red Hat Enterprise Linux 4. 

All users of X11 should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/136941" id="136941">font corruption on openoffice.org menus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143910" id="143910">X is unusable on GeForce 6600GT with nForce4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150036" id="150036">CAN-2005-0605 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157962" id="157962">xorg-x11-6.8.1-23 missing half of Lucida fonts</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198024" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198022" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198030" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198034" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198032" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198028" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198062" comment="fonts-xorg-ISO8859-15-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198063" comment="fonts-xorg-ISO8859-15-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198042" comment="fonts-xorg-truetype is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198043" comment="fonts-xorg-truetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198040" comment="fonts-xorg-base is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198041" comment="fonts-xorg-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198052" comment="fonts-xorg-ISO8859-2-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198053" comment="fonts-xorg-ISO8859-2-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198060" comment="fonts-xorg-ISO8859-14-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198061" comment="fonts-xorg-ISO8859-14-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198054" comment="fonts-xorg-ISO8859-9-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198055" comment="fonts-xorg-ISO8859-9-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198044" comment="fonts-xorg-syriac is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198045" comment="fonts-xorg-syriac is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198064" comment="fonts-xorg-ISO8859-15-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198065" comment="fonts-xorg-ISO8859-15-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198046" comment="fonts-xorg-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198047" comment="fonts-xorg-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198050" comment="fonts-xorg-ISO8859-2-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198051" comment="fonts-xorg-ISO8859-2-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198048" comment="fonts-xorg-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198049" comment="fonts-xorg-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198066" comment="fonts-xorg-cyrillic is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198067" comment="fonts-xorg-cyrillic is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198058" comment="fonts-xorg-ISO8859-14-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198059" comment="fonts-xorg-ISO8859-14-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198056" comment="fonts-xorg-ISO8859-9-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198057" comment="fonts-xorg-ISO8859-9-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198038" comment="fonts-xorg is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198039" comment="fonts-xorg is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050201" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:201: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:201-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-201.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles fully qualified domain name (FQDN)
lookups.  A malicious DNS server could crash Squid by sending a carefully
crafted DNS response to an FQDN lookup.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0446 to
this issue.  
 
This erratum also includes two minor patches to the LDAP helpers.  One 
corrects a slight malformation in ldap search requests (although all 
known LDAP servers accept the requests).  The other adds documentation 
for the -v option to the ldap helpers. 
 
Users of Squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050201002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050213" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:213: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:213-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-213.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). RHSA-2004:592 contained a fix for this issue, but it was
found to be incomplete and left 64-bit architectures vulnerable. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue.

All users of xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135393" id="135393">CAN-2004-0888 xpdf integer overflows (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050213002" comment="xpdf is earlier than 1:2.02-9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050215" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:215: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:215-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-215.html" />
          <reference source="CVE" ref_id="CVE-2005-0208" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0208.html" />
          <reference source="CVE" ref_id="CVE-2005-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0472.html" />
          <reference source="CVE" ref_id="CVE-2005-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0473.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

Two HTML parsing bugs were discovered in Gaim. It is possible that a remote
attacker could send a specially crafted message to a Gaim client, causing
it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0208 and CAN-2005-0473 to
these issues.

A bug in the way Gaim processes SNAC packets was discovered.  It is
possible that a remote attacker could send a specially crafted SNAC packet
to a Gaim client, causing the client to stop responding.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0472 to this issue.

Additionally, various client crashes, memory leaks, and protocol issues
have been resolved.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.1.4 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-10" />
        <updated date="2005-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0208.html">CVE-2005-0208</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0472.html">CVE-2005-0472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0473.html">CVE-2005-0473</cve>
                <bugzilla href="http://bugzilla.redhat.com/149273" id="149273">CAN-2005-0472 Gaim DoS issues (CAN-2005-0473)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149533" id="149533">CAN-2005-0208 Gaim HTML parsing DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215002" comment="gaim is earlier than 1:1.1.4-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215005" comment="gaim is earlier than 1:1.1.4-1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050232" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:232: ipsec-tools security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:232-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-232.html" />
          <reference source="CVE" ref_id="CVE-2005-0398" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0398.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel. The ipsec-tools package includes:

- setkey, a program to directly manipulate policies and SAs
- racoon, an IKEv1 keying daemon

A bug was found in the way the racoon daemon handled incoming ISAKMP
requests.  It is possible that an attacker could crash the racoon daemon by
sending a specially crafted ISAKMP packet.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0398 to
this issue. 

Additionally, the following issues have been fixed:
- racoon mishandled restarts in the presence of stale administration sockets.
- on Red Hat Enterprise Linux 4, racoon and setkey did not properly set up
  forward policies, which prevented tunnels from working.

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0398.html">CVE-2005-0398</cve>
                <bugzilla href="http://bugzilla.redhat.com/145531" id="145531">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145535" id="145535">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148950" id="148950">racoon unable to start with stale socket /tmp/.racoon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150179" id="150179">ipsec/racoon/setkey does not properly forward packets to vpn peer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232002" comment="ipsec-tools is earlier than 0:0.2.5-0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232005" comment="ipsec-tools is earlier than 0:0.3.3-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050235" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:235: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:235-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-235.html" />
          <reference source="CVE" ref_id="CVE-2004-1177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1177.html" />
    
    <description>Mailman manages electronic mail discussion and e-newsletter lists. 

A cross-site scripting (XSS) flaw in the driver script of mailman prior to
version 2.1.5 could allow remote attackers to execute scripts as other web
users. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1177 to this issue.

Users of mailman should update to this erratum package, which corrects this
issue by turning on STEALTH_MODE by default and using Utils.websafe() to
quote the html.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1177.html">CVE-2004-1177</cve>
                <bugzilla href="http://bugzilla.redhat.com/132750" id="132750">Mailman doesn't work with courier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142605" id="142605">init script doesn't use /var/lock/subsys</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143008" id="143008">mailman logrotate has wrong location for mailmanctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147833" id="147833">CAN-2004-1177 - mailman</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235002" comment="mailman is earlier than 3:2.1.5-25.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235005" comment="mailman is earlier than 3:2.1.5-33.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050238" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:238: evolution security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-238.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools. Evolution includes a mailer, calendar, contact manager, and
communication facility.  The tools which make up Evolution are tightly
integrated with one another and act as a seamless personal information
management tool.

A bug was found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default. Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

Additionally, these updated packages address the following issues:

-- If evolution ran during a GNOME session, the evolution-wombat process 
   did not exit when the user logged out of the desktop.

-- For folders marked for Offline Synchronization: if a user moved a
   message from a Local Folder to an IMAP folder while in
   Offline mode, the message was not present in either folder after
   returning to Online mode.
 
   This update fixes this problem. Email messages that have been lost 
   this way may still be present in the following path: 

   ~/evolution/&amp;lt;NAME_OF_MAIL_STORE&amp;gt;/ \
   &amp;lt;path-to-folder-via-subfolder-directories&amp;gt;/ \
   &amp;lt;temporary-uid-of-message&amp;gt;

If this bug has affected you it may be possible to recover data by
examining the contents of this directory.

All users of evolution should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
                <bugzilla href="http://bugzilla.redhat.com/125528" id="125528">Moving to IMAP folder while offline eats mail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155376" id="155376">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157352" id="157352">.ics import crashes Evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157354" id="157354">Creating a meeting crashes evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157355" id="157355">Cannot create all day event in calendar</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238002" comment="evolution is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238004" comment="evolution-devel is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050256" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:256: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-256.html" />
          <reference source="CVE" ref_id="CVE-2004-1453" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1453.html" />
    
    <description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

It was discovered that the use of LD_DEBUG, LD_SHOW_AUXV, and
LD_DYNAMIC_WEAK were not restricted for a setuid program. A local user
could utilize this flaw to gain information, such as the list of symbols
used by the program. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1453 to this issue.

This erratum addresses the following bugs in the GNU C Library:

- fix stack alignment in IA-32 clone
- fix double free in globfree
- fix fnmatch to avoid jumping based on unitialized memory read
- fix fseekpos after ungetc
- fix TZ env var handling if the variable ends with + or -
- avoid depending on values read from unitialized memory in strtold
  on certain architectures
- fix mapping alignment computation in dl-load
- fix i486+ strncat inline assembly
- make gethostid/sethostid work on bi-arch platforms
- fix ppc64 getcontext/swapcontext
- fix pthread_exit if called after pthread_create, but before the created
  thread actually started
- fix return values for tgamma (+-0)
- fix handling of very long lines in /etc/hosts
- avoid page aliasing of thread stacks on AMD64
- avoid busy loop in malloc if concurrent with fork
- allow putenv and setenv in shared library constructors
- fix restoring of CCR in swapcontext and getcontext on ppc64
- avoid using sigaction (SIGPIPE, ...) in syslog implementation

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1453.html">CVE-2004-1453</cve>
                <bugzilla href="http://bugzilla.redhat.com/135125" id="135125">telnet: 0: Name or service not known</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138439" id="138439">re_compile_pattern segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140378" id="140378">[RHEL3] glibc behavior with long lines in /etc/hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142617" id="142617">[RHEL3] libc's getXXent and getXXbyYY are inefficient for large groups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143279" id="143279">x86_64 ecvt() returns "inf" for valid denormalized doubles</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146210" id="146210">zdump -v GMT segfaults in x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146402" id="146402">CAN-2004-1453 Information leak with LD_DEBUG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146710" id="146710">pthread_getspecific gets non-NULL value for new key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147478" id="147478">nscd fails with big group in ldap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149205" id="149205">malloc: top chunk is corrupt w/ MALLOC_CHECK_=3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256012" comment="glibc-common is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256006" comment="glibc-headers is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256008" comment="nptl-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256004" comment="glibc-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256016" comment="glibc-debug is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256010" comment="glibc-profile is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256002" comment="glibc is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256014" comment="nscd is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256018" comment="glibc-utils is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050267" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:267: Evolution security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-267.html" />
          <reference source="CVE" ref_id="CVE-2005-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2549.html" />
          <reference source="CVE" ref_id="CVE-2005-2550" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2550.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in Evolution.  If a user tries to save a
carefully crafted meeting or appointment, arbitrary code may be executed as
the user running Evolution. The Common Vulnerabilities and Exposures
project has assigned the name CAN-2005-2550 to this issue.

Additionally, several other format string bugs were found in Evolution. If
a user views a malicious vCard, connects to a malicious LDAP server, or
displays a task list from a malicious remote server, arbitrary code may be
executed as the user running Evolution. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2005-2549 to this issue. Please
note that this issue only affects Red Hat Enterprise Linux 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-29" />
        <updated date="2005-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2549.html">CVE-2005-2549</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2550.html">CVE-2005-2550</cve>
                <bugzilla href="http://bugzilla.redhat.com/165235" id="165235">CAN-2005-2549 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL4) (CAN-2005-2550)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165236" id="165236">CAN-2005-2550 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL3)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267002" comment="evolution is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267004" comment="evolution-devel is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267007" comment="evolution is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267008" comment="evolution-devel is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050271" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:271: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:271-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-271.html" />
          <reference source="CVE" ref_id="CVE-2005-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0455.html" />
          <reference source="CVE" ref_id="CVE-2005-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0611.html" />
    
    <description>HelixPlayer is a media player.

A stack based buffer overflow bug was found in HelixPlayer's Synchronized
Multimedia Integration Language (SMIL) file processor. An attacker could
create a specially crafted SMIL file which would execute arbitrary code
when opened by a user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0455 to this issue.

A buffer overflow bug was found in the way HelixPlayer decodes WAV files.
An attacker could create a specially crafted WAV file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0611 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer 1.0.3 which is not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0455.html">CVE-2005-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0611.html">CVE-2005-0611</cve>
                <bugzilla href="http://bugzilla.redhat.com/150098" id="150098">CAN-2005-0455 buffer overflow in helixplayer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150103" id="150103">CAN-2005-0611 .wav overflow in helixplayer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271002" comment="HelixPlayer is earlier than 1:1.0.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050277" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:277: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:277-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-277.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the Mozilla string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Please note that other security issues have been found that affect Mozilla.
These other issues have a lower severity, and are therefore planned to be
released as additional security updates in the future.

Users of Mozilla should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/150124" id="150124">CAN-2005-0255 Memory overwrite in string library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277010" comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277012" comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277004" comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277020" comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277002" comment="mozilla is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277016" comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277014" comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277008" comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277006" comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277018" comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050293" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:293: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:293-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-293.html" />
          <reference source="CVE" ref_id="CVE-2004-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0075.html" />
          <reference source="CVE" ref_id="CVE-2004-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0177.html" />
          <reference source="CVE" ref_id="CVE-2004-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0814.html" />
          <reference source="CVE" ref_id="CVE-2004-1058" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1058.html" />
          <reference source="CVE" ref_id="CVE-2004-1073" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1073.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0137" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0137.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0403.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
    
    <description>The following security issues were fixed:

The Vicam USB driver did not use the copy_from_user function to access
userspace, crossing security boundaries. (CAN-2004-0075)

The ext3 and jfs code did not properly initialize journal descriptor
blocks.  A privileged local user could read portions of kernel memory.
(CAN-2004-0177)

The terminal layer did not properly lock line discipline changes or pending
IO.  An unprivileged local user could read portions of kernel memory, or
cause a denial of service (system crash). (CAN-2004-0814)

A race condition was discovered.  Local users could use this flaw to read
the environment variables of another process that is still spawning via
/proc/.../cmdline. (CAN-2004-1058)

A flaw in the execve() syscall handling was discovered, allowing a local
user to read setuid ELF binaries that should otherwise be protected by
standard permissions. (CAN-2004-1073).  Red Hat originally reported this
as being fixed by RHSA-2004:549, but the associated fix was missing from
that update.

Keith Owens reported a flaw in the Itanium unw_unwind_to_user() function.
A local user could use this flaw to cause a denial of service (system
crash) on the Itanium architecture. (CAN-2005-0135)

A missing Itanium syscall table entry could allow an unprivileged
local user to cause a denial of service (system crash) on the Itanium
architecture. (CAN-2005-0137)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architectures was discovered.  A local user could use this flaw to
access privileged IO ports. (CAN-2005-0204)

A flaw was discovered in the Linux PPP driver.  On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 was
discovered that left a pointer to a freed tty structure.  A local user
could potentially use this flaw to cause a denial of service (system crash)
or possibly gain read or write access to ttys that should normally be
prevented. (CAN-2005-0403)

A flaw in fragment queuing was discovered affecting the netfilter
subsystem.  On systems configured to filter or process network packets (for
example those configured to do firewalling), a remote attacker could send a
carefully crafted set of fragmented packets to a machine and cause a denial
of service (system crash).  In order to sucessfully exploit this flaw, the
attacker would need to know (or guess) some aspects of the firewall ruleset
in place on the target system to be able to craft the right fragmented
packets. (CAN-2005-0449)

Missing validation of an epoll_wait() system call parameter could allow
a local user to cause a denial of service (system crash) on the IBM S/390
and zSeries architectures. (CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered.  A local
user could potentially use this flaw to cause a denial of service (system
crash). (CAN-2005-0749)

A flaw was discovered in the bluetooth driver system.  On system where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

In addition to the security issues listed above, there was an important
fix made to the handling of the msync() system call for a particular case
in which the call could return without queuing modified mmap()'ed data for
file system update. (BZ 147969)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

Red Hat Enterprise Linux 3 users are advised to upgrade their kernels to
the packages associated with their machine architectures/configurations

Please note that the fix for CAN-2005-0449 required changing the
external symbol linkages (kernel module ABI) for the ip_defrag()
and ip_ct_gather_frags() functions.  Any third-party module using either
of these would also need to be fixed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-22" />
        <updated date="2005-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0075.html">CVE-2004-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0177.html">CVE-2004-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0814.html">CVE-2004-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1058.html">CVE-2004-1058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1073.html">CVE-2004-1073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0137.html">CVE-2005-0137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0403.html">CVE-2005-0403</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
                <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293004" comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293002" comment="kernel is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293006" comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293016" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293018" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293014" comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050294" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:294: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 5 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:294-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-294.html" />
          <reference source="CVE" ref_id="CVE-2005-0757" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0757.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the fifth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - support for 2-TB partitions on block devices
  - support for new disk, network, and USB devices
  - support for clustered APIC mode on AMD64 NUMA systems
  - netdump support on AMD64, Intel EM64T, Itanium, and ppc64 systems
  - diskdump support on sym53c8xx and SATA piix/promise adapters
  - NMI switch support on AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 3.

Some key areas affected by these fixes include the kernel's networking,
SATA, TTY, and USB subsystems, as well as the architecture-dependent
handling under the ia64, ppc64, and x86_64 directories.  Scalability
improvements were made primarily in the memory management and file
system areas.

A flaw in offset handling in the xattr file system code backported to
Red Hat Enterprise Linux 3 was fixed.  On 64-bit systems, a user who
can access an ext3 extended-attribute-enabled file system could cause
a denial of service (system crash).  This issue is rated as having a
moderate security impact (CAN-2005-0757).

The following device drivers have been upgraded to new versions:

  3c59x ------ LK1.1.18
  3w-9xxx ---- 2.24.00.011fw (new in Update 5)
  3w-xxxx ---- 1.02.00.037
  8139too ---- (upstream 2.4.29)
  b44 -------- 0.95
  cciss ------ v2.4.54.RH1
  e100 ------- 3.3.6-k2
  e1000 ------ 5.6.10.1-k2
  lpfcdfc ---- 1.0.13 (new in Update 5)
  tg3 -------- 3.22RH

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0757.html">CVE-2005-0757</cve>
                <bugzilla href="http://bugzilla.redhat.com/116289" id="116289">BLKPG_ADD_PARTITION op of BLKPG ioctl doesn't let you add partitions >= 1TB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119351" id="119351">Getting OOM errors on an unconstrained system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121716" id="121716">Raw device I/O transfer size limited to 32KB.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123415" id="123415">API Breakage: NFS "No locks available" with kernel 2.4.21-15.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124600" id="124600">Unexpected error: VFS: Busy inodes after unmount. Self-destruct in 5 seconds.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127066" id="127066">Panic is occurring in the I/O completion interrupt handling for the character interface driver (sg).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128176" id="128176">Add the 3w-9xxx module (required for the 9000 series 3ware cards)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129084" id="129084">ICH6 SATA support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130113" id="130113">Strange output of /proc/mtrr</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130365" id="130365">Request to include EMC Celerra and iSCSI devices to the black list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131981" id="131981">O_DIRECT doesn't work on LVM devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132162" id="132162">NFS intr flag prevents core dumps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132257" id="132257">LTC-8859: softdog.o need to be included into RHEL distributions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132339" id="132339">x86 compatibility mode apps using signals crash under EM64T</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132494" id="132494">POSIX Asynchronous IO support is unstable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132838" id="132838">Kernel Panic: Unable to satisfy kernel paging request... when starting ServerVantage.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133020" id="133020">[RHEL3][IA32E][X86_64]Wrong FPU IP and DP in the SIGFPE signal context</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133388" id="133388">3c59x: eth0: Transmit error, Tx status register d0. (10Mb hub)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133905" id="133905">kernel crash, fatal exception, accessing /proc, EXT3-fs error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134832" id="134832">Ia32e + Intel SATA 82801EB + kernel 2.4.21-20EL;   unable to mount root partition.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135266" id="135266">Panics while backing up LVM snapshots</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135583" id="135583">RHEL3U3 panics on boot for HP rx5670</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135688" id="135688">NFS ESTALES returned on open [IT50092]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136317" id="136317">When copying rootfs to /mnt/sdc/, rsync accessed /proc/kcore and kernel crashed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136398" id="136398">NFS direct reads don't flush dirty cached pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137201" id="137201">RHEL3U2/U3 x86-64 - /proc/mtrr reported incorrectly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137519" id="137519">ps shows bad PPID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137830" id="137830">worktodo does not support NFS aio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137961" id="137961">tg3 fiber auto-negotiation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138182" id="138182">Kernel hang when cat'ting file on intr NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138240" id="138240">MCA in tulip on ifconfig down/reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138815" id="138815">[RHEL3-U5][Diskdump] Stalls before printing "CPU frozen"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138827" id="138827">usb: raced timeout errors when using usb/serial adapter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138905" id="138905">Unkillable processes under 64bit Linux which use Kernel Asynchronous I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139421" id="139421">[RHEL3-U4][Diskdump] Diskdump failed with serial console enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139434" id="139434">[RHEL3-U4][Diskdump] Segmentation Fault after cliloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139440" id="139440">[RHEL3-U5][Diskdump] All CPUs are displayed in CPU frozen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139465" id="139465">em64t/ia32e kernel panic: 'interrupt handler - not syncing' during heavy network I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140083" id="140083">lx-choptp19 crashed running 2.4.21-20.EL.BZ131027.hotfixhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140331" id="140331">stack overflows can occur on x86_64 under stack pressure when softirq's are handled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140552" id="140552">Kernel wrongly complains about application bug when loading modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140585" id="140585">[RHEL3][PATCH] SIOCGHWADDR does not clear buffer for ppp connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140616" id="140616">RHEL3 PATCH dev.c: clear SIOCGIFHWADDR buffer if !dev->addr_len</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140790" id="140790">e100 and e1000 drivers should return EINVAL when ethtool tries to set rx-mini or rx-jumbo</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141282" id="141282">nptl futex_wait fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141377" id="141377">[PATCH] memory leak in ipv6   ip6_{push,flush}_pending_frames()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141388" id="141388">FAT32 file system zero length files corruption after remount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141697" id="141697">ATAPI-CDROM not accessible with kernel options ide-scsi and swiotlb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141757" id="141757">Infinite loop when syncing over automounted NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142683" id="142683">bonding with mii monitoring does not work with realtek card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142725" id="142725">[PATCH] video1394 fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142954" id="142954">sata_sx4 4GB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143542" id="143542">Unable to handle kernel NULL pointer dereference at virtual address 00000004</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143565" id="143565">NIC BCM4401 on Dell Inspiron 5100 broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143625" id="143625">kernel can not register scsi LUNs above 7 for mylexFFx2 FC RAID controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144260" id="144260">U4 kernel sound broken on certain AC 97 systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144360" id="144360">Fibre Channel tape speed regression (qla2200)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144990" id="144990">Anaconda installer partion error large RAID volume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145331" id="145331">kernel panic in get_signal_to_deliver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145409" id="145409">panic_on_oops hook removed on ia64 by diskdump patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145563" id="145563">tar crashes DELL server every 4th day.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145746" id="145746">mmap() system call can return Nil</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146345" id="146345">recv returns EAGAIN instead of EINTR when interrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146501" id="146501">ext2/ext3 w/ 1024 blocksize eats all memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147541" id="147541">rsync creating truncated files on fat32 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147580" id="147580">Race condition in md subsystem causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147704" id="147704">laus incorrectly truncates path string when predicate filter is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151934" id="151934">Running lshw causes MCA on Olympia rx8620</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152627" id="152627">sata_sil missing PCI IDs for ATI SATA controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152959" id="152959">Repeated Kernel Panics while using LVM Snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156617" id="156617">SIGCHLD set to SIG_IGN but calls wait().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156882" id="156882">aggressively clean bhs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156928" id="156928">sata_promise in 2.4.21-27.0.4.EL doesn't support Promise sataII 150 tx4 yet</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294006" comment="kernel-source is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294002" comment="kernel is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294008" comment="kernel-doc is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294018" comment="kernel-hugemem is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294014" comment="kernel-BOOT is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294004" comment="kernel-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294012" comment="kernel-smp is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050300" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:300: libexif security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:300-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-300.html" />
          <reference source="CVE" ref_id="CVE-2005-0664" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0664.html" />
    
    <description>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

A bug was found in the way libexif parses EXIF tags. An attacker could
create a carefully crafted EXIF image file which could cause image viewers
linked against libexif to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0664 to this issue.

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0664.html">CVE-2005-0664</cve>
                <bugzilla href="http://bugzilla.redhat.com/150503" id="150503">CAN-2005-0664 buffer overflow in libexif</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300004" comment="libexif-devel is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300005" comment="libexif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300002" comment="libexif is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300003" comment="libexif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050306" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:306: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:306-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-306.html" />
          <reference source="CVE" ref_id="CVE-2005-0699" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0699.html" />
          <reference source="CVE" ref_id="CVE-2005-0704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0704.html" />
          <reference source="CVE" ref_id="CVE-2005-0705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0705.html" />
          <reference source="CVE" ref_id="CVE-2005-0739" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0739.html" />
          <reference source="CVE" ref_id="CVE-2005-0765" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0765.html" />
          <reference source="CVE" ref_id="CVE-2005-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0766.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.


A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.

A buffer overflow flaw was discovered in the Etheric dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0704 to this issue.

The GPRS-LLC dissector could crash if the "ignore cipher bit" option was
set. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0705 to this issue.

A buffer overflow flaw was discovered in the 3GPP2 A11 dissector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0699 to this issue.

A buffer overflow flaw was discovered in the IAPP dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0739 to this issue.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-18" />
        <updated date="2005-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0699.html">CVE-2005-0699</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0704.html">CVE-2005-0704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0705.html">CVE-2005-0705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0739.html">CVE-2005-0739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0765.html">CVE-2005-0765</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0766.html">CVE-2005-0766</cve>
                <bugzilla href="http://bugzilla.redhat.com/150705" id="150705">CAN-2005-0699 Multiple ethereal issues (CAN-2005-0704 CAN-2005-0705)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306004" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306002" comment="ethereal is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306008" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306007" comment="ethereal is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050307" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:307: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-307.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

Users of KDE should upgrade to these erratum packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-06" />
        <updated date="2005-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/151373" id="151373">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307002" comment="kdelibs is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307004" comment="kdelibs-devel is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050320" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:320: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:320-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-320.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

Additionally, a bug was fixed which caused ImageMagick(TM) to occasionally
segfault when writing TIFF images to standard output.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/142045" id="142045">Segmentation fault on conversion to TIFF (possible libtiff bug)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320010" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320004" comment="ImageMagick-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320006" comment="ImageMagick-perl is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320002" comment="ImageMagick is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320008" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050323" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:323: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:323-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-323.html" />
          <reference source="CVE" ref_id="CVE-2004-0906" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0906.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2004-1613" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1613.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0147.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1380 to this issue.

A bug was found in the way Mozilla allowed plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0232 to this issue.

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0149 to
this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0147 to this issue.

A bug was found in the way Mozilla handles certain start tags followed by a
NULL character.  A malicious web page could cause Mozilla to crash when
viewed by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1613 to this issue.

A bug was found in the way Mozilla sets file permissions when installing
XPI packages.  It is possible for an XPI package to install some files
world readable or writable, allowing a malicious local user to steal
information or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0906 to
this issue.

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0141 to this issue.

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0144 to this issue.

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.4.4 and additional backported patches to correct
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0906.html">CVE-2004-0906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1613.html">CVE-2004-1613</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0147.html">CVE-2005-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
                <bugzilla href="http://bugzilla.redhat.com/145597" id="145597">CAN-2005-0141 Link opened in new tab can load a local file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145609" id="145609">CAN-2005-0144 Secure site lock can be spoofed with view-source:</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145610" id="145610">CAN-2004-1380 Input stealing from other tabs (CAN-2004-1381)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145614" id="145614">CAN-2005-0147 Browser responds to proxy auth request from non-proxy server (ssl/https)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145615" id="145615">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151209" id="151209">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151492" id="151492">CAN-2004-1613 Mozilla start tag NULL character DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151494" id="151494">CAN-2004-0906 Mozilla XPI installer insecure file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151496" id="151496">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323018" comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323014" comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323016" comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323010" comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323002" comment="mozilla is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323020" comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323006" comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323004" comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323012" comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323008" comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050325" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:325: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-325.html" />
          <reference source="CVE" ref_id="CVE-2005-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0237.html" />
          <reference source="CVE" ref_id="CVE-2005-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0365.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

The International Domain Name (IDN) support in the Konqueror browser
allowed remote attackers to spoof domain names using punycode encoded
domain names.  Such domain names are decoded in URLs and SSL certificates
in a way that uses homograph characters from other character sets, which
facilitates phishing attacks. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0237 to this issue.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

A flaw in the dcopidlng script was discovered. The dcopidlng script would
create temporary files with predictable filenames which could allow local
users to overwrite arbitrary files via a symlink attack. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0365 to this issue.

Users of KDE should upgrade to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0237.html">CVE-2005-0237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0365.html">CVE-2005-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/147405" id="147405">CAN-2005-0237 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148822" id="148822">CAN-2005-0365 dcopidlng insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150090" id="150090">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325002" comment="kdelibs is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325004" comment="kdelibs-devel is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050327" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:327: telnet security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-327.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>The telnet package provides a command line telnet client. The telnet-server
package includes a telnet daemon, telnetd, that supports remote login to
the host machine.

Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468
and CAN-2005-0469 to these issues.

Additionally, the following bugs have been fixed in these erratum packages
for Red Hat Enterprise Linux 2.1 and Red Hat Enterprise Linux 3:

- telnetd could loop on an error in the child side process

- There was a race condition in telnetd on a wtmp lock on some occasions

- The command line in the process table was sometimes too long and caused
bad output from the ps command

- The 8-bit binary option was not working

Users of telnet should upgrade to this updated package, which contains
backported patches to correct these issues.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/126858" id="126858">Too long /proc/X/cmdline: bad ps output when piped to less/more</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145004" id="145004">telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145636" id="145636">[PATCH] telnetd loops on child IO error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147003" id="147003">[RHEL3] telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151297" id="151297">CAN-2005-0469 slc_add_reply() Buffer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151301" id="151301">CAN-2005-0468 env_opt_add() Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327002" comment="telnet is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327004" comment="telnet-server is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327007" comment="telnet is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327008" comment="telnet-server is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050330" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:330: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:330-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-330.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

The krb5-workstation package includes a Kerberos-aware telnet client. 
Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468 and
CAN-2005-0469 to these issues.

Users of krb5 should update to these erratum packages which contain a
backported patch to correct this issue.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/151267" id="151267">CAN-2005-0469  Multiple Telnet Client issues (CAN-2005-0468)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330006" comment="krb5-libs is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330004" comment="krb5-devel is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330008" comment="krb5-server is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330002" comment="krb5 is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330010" comment="krb5-workstation is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330015" comment="krb5-libs is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330014" comment="krb5-devel is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330016" comment="krb5-server is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330013" comment="krb5 is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330017" comment="krb5-workstation is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050331" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:331: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:331-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-331.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
malicious XPM file that would execute arbitrary code if opened by a victim
using an application linked to the vulnerable library. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0605 to this issue.

The updated XFree86 packages also address the following minor issues:

- Updated XFree86-4.3.0-keyboard-disable-ioport-access-v3.patch to make
  warning messages less alarmist.

- Backported XFree86-4.3.0-libX11-stack-overflow.patch from xorg-x11-6.8.1
  packaging to fix stack overflow in libX11, which was discovered by new
  security features of gcc4.

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/132885" id="132885">libX11 overflows it's own stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150038" id="150038">CAN-2005-0605 XPM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331012" comment="XFree86-xdm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331016" comment="XFree86-libs-data is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331046" comment="XFree86-doc is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331002" comment="XFree86 is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331014" comment="XFree86-libs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331060" comment="XFree86-sdk is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331008" comment="XFree86-xfs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331048" comment="XFree86-Xnest is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331058" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331018" comment="XFree86-base-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331006" comment="XFree86-font-utils is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331052" comment="XFree86-tools is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331050" comment="XFree86-Xvfb is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331010" comment="XFree86-twm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331054" comment="XFree86-xauth is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331004" comment="XFree86-devel is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050332" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:332: xloadimage security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-332.html" />
          <reference source="CVE" ref_id="CVE-2005-0638" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0638.html" />
    
    <description>The xloadimage utility displays images in an X Window System window,
loads images into the root window, or writes images into a file.
Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM,
and XBM).

A flaw was discovered in xloadimage where filenames were not properly
quoted when calling the gunzip command.  An attacker could create a file
with a carefully crafted filename so that it would execute arbitrary
commands if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0638 to
this issue.

Another bug in xloadimage would cause it to crash if called with certain
invalid TIFF, PNM, PBM, or PPM file names.

All users of xloadimage should upgrade to this erratum package which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-04-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0638.html">CVE-2005-0638</cve>
                <bugzilla href="http://bugzilla.redhat.com/70867" id="70867">xloadimage crashes with some TIFF images</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/78481" id="78481">bad source code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150700" id="150700">CAN-2005-0638 xloadimage multiple issues.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332002" comment="xloadimage is earlier than 0:4.1-34.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332005" comment="xloadimage is earlier than 0:4.1-34.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050334" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:334: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:334-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-334.html" />
          <reference source="CVE" ref_id="CVE-2005-0709" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0709.html" />
          <reference source="CVE" ref_id="CVE-2005-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0710.html" />
          <reference source="CVE" ref_id="CVE-2005-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0711.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes several security risks in the MySQL server.

Stefano Di Paola discovered two bugs in the way MySQL handles user-defined
functions. A user with the ability to create and execute a user defined
function could potentially execute arbitrary code on the MySQL server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2005-0709 and CAN-2005-0710 to these issues.

Stefano Di Paola also discovered a bug in the way MySQL creates temporary
tables. A local user could create a specially crafted symlink which could
result in the MySQL server overwriting a file which it has write access to.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-0711 to this issue.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0709.html">CVE-2005-0709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0710.html">CVE-2005-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0711.html">CVE-2005-0711</cve>
                <bugzilla href="http://bugzilla.redhat.com/150868" id="150868">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150871" id="150871">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151051" id="151051">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152344" id="152344">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334002" comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334004" comment="mysql-server is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334008" comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334006" comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334011" comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334012" comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334014" comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334013" comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050335" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:335: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:335-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-335.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. (CAN-2005-0147)

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. (CAN-2004-1380)

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. (CAN-2005-0149)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Mozilla saves temporary files. Temporary files
are saved with world readable permissions, which could allow a local
malicious user to view potentially sensitive data. (CAN-2005-0142)

A bug was found in the way Mozilla handles synthetic middle click events. 
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

A bug was found in the way Mozilla processes XUL content.  If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. (CAN-2005-0141)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. (CAN-2005-0144)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can display the secure site icon by loading a binary
file from a secured site. (CAN-2005-0143)

A bug was found in the way Mozilla displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.6 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
                <bugzilla href="http://bugzilla.redhat.com/142508" id="142508">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144228" id="144228">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146188" id="146188">CAN-2005-0141 multiple mozilla issues CAN-2004-1316 CAN-2005-0142 CAN-2005-0143 CAN-2005-0144 CAN-2004-1380 CAN-2004-1381 CAN-2005-0146 CAN-2005-0147 CAN-2005-0149</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150866" id="150866">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151730" id="151730">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335018" comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335014" comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335016" comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335010" comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335002" comment="mozilla is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335020" comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335006" comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335004" comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335012" comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335008" comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335022" comment="devhelp is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335026" comment="evolution is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335028" comment="evolution-devel is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050336" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:336: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-336.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0402.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A buffer overflow bug was found in the way Firefox processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Firefox processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0401 to this issue.

A bug was found in the way Firefox bookmarks content to the sidebar. If a
user can be tricked into bookmarking a malicious web page into the sidebar
panel, that page could execute arbitrary programs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0402 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0402.html">CVE-2005-0402</cve>
                <bugzilla href="http://bugzilla.redhat.com/150877" id="150877">CAN-2005-0399 firefox GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151153" id="151153">CAN-2005-0402 arbitrary code execution via sidebar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151714" id="151714">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050336002" comment="firefox is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050337" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:337: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-337.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A buffer overflow bug was found in the way Thunderbird processes GIF
images. It is possible for an attacker to create a specially crafted GIF
image, which when viewed by a victim will execute arbitrary code as the
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0399 to this issue.

A bug was found in the Thunderbird string handling functions. If a
malicious website is able to exhaust a system's memory, it becomes possible
to execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Users of Thunderbird are advised to upgrade to this updated package which
contains Thunderbird version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/149883" id="149883">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150874" id="150874">CAN-2005-0399 thunderbird GIF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050337002" comment="thunderbird is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050340" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:340: curl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:340-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-340.html" />
          <reference source="CVE" ref_id="CVE-2005-0490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0490.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and
Dict servers, using any of the supported protocols. cURL is designed
to work without user interaction or any kind of interactivity. 

Multiple buffer overflow bugs were found in the way curl processes base64
encoded replies. If a victim can be tricked into visiting a URL with curl,
a malicious web server could execute arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0490 to this issue.

All users of curl are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0490.html">CVE-2005-0490</cve>
                <bugzilla href="http://bugzilla.redhat.com/149322" id="149322">CAN-2005-0490 Multiple stack based buffer overflows in curl</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340002" comment="curl is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340004" comment="curl-devel is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340007" comment="curl is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340008" comment="curl-devel is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050343" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:343: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-343.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gdk-pixbuf. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gdk-pixbuf are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152315" id="152315">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343002" comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343009" comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050344" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:344: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-344.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

A bug was found in the way gtk2 processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gtk2. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gtk2 are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152317" id="152317">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344002" comment="gtk2 is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344004" comment="gtk2-devel is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344007" comment="gtk2 is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344008" comment="gtk2-devel is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050345" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:345: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:345-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-345.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- Files with a size of 2 GB and larger were not entered into the slocate
  database.

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems).

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/132571" id="132571">Files > 2 GB are not entered into slocate data base</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169453" id="169453">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050345002" comment="slocate is earlier than 0:2.7-3.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050346" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:346: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-346.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems.)

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

- The default configuration excluded /mnt/floppy, but not /media.

- The default configuration did not exclude nfs4 file systems.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152253" id="152253">Incorrect path in /etc/updatedb.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156091" id="156091">updatedb indexes nfs4 filesystems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165430" id="165430">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050346002" comment="slocate is earlier than 0:2.7-13.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050354" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:354: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-354.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>TeTeX is an implementation of TeX for Linux or UNIX systems. TeX takes
a text file and a set of formatting commands as input and creates a
typesetter-independent .dvi (DeVice Independent) file as output.

A number of security flaws have been found affecting libraries used
internally within teTeX.  An attacker who has the ability to trick a user
into processing a malicious file with teTeX could cause teTeX to crash or
possibly execute arbitrary code. 

A number of integer overflow bugs that affect Xpdf were discovered. The
teTeX package contains a copy of the Xpdf code used for parsing PDF files
and is therefore affected by these bugs. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0888 and
CAN-2004-1125 to these issues.

A number of integer overflow bugs that affect libtiff were discovered.  The
teTeX package contains an internal copy of libtiff used for parsing TIFF
image files and is therefore affected by these bugs.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0803, CAN-2004-0804 and CAN-2004-0886 to these issues.

Also latex2html is added to package tetex-latex for 64bit platforms.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/137475" id="137475">CAN-2004-0888 xpdf integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137607" id="137607">CAN-2004-0803 multiple issues in libtiff (CAN-2004-0804 CAN-2004-0886)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137973" id="137973">tetex-latex package missing latex2html</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145129" id="145129">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354006" comment="tetex-xdvi is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354002" comment="tetex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354012" comment="tetex-fonts is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354014" comment="tetex-doc is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354004" comment="tetex-latex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354008" comment="tetex-dvips is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354010" comment="tetex-afm is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050357" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:357: gzip security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-357.html" />
          <reference source="CVE" ref_id="CVE-2005-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0758.html" />
          <reference source="CVE" ref_id="CVE-2005-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0988.html" />
          <reference source="CVE" ref_id="CVE-2005-1228" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1228.html" />
    
    <description>The gzip package contains the GNU gzip data compression program.

A bug was found in the way zgrep processes file names. If a user can be
tricked into running zgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running zgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0758 to this issue.

A bug was found in the way gunzip modifies permissions of files being
decompressed. A local attacker with write permissions in the directory in
which a victim is decompressing a file could remove the file being written
and replace it with a hard link to a different file owned by the victim. 
gunzip then gives the linked file the permissions of the uncompressed file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0988 to this issue.

A directory traversal bug was found in the way gunzip processes the -N
flag. If a victim decompresses a file with the -N flag, gunzip fails to
sanitize the path which could result in a file owned by the victim being
overwritten. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1228 to this issue.

Users of gzip should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0758.html">CVE-2005-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0988.html">CVE-2005-0988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1228.html">CVE-2005-1228</cve>
                <bugzilla href="http://bugzilla.redhat.com/121514" id="121514">CAN-2005-0758 zgrep has security issue in sed usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155745" id="155745">CAN-2005-0988 Race condition in gzip</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156266" id="156266">CAN-2005-1228 directory traversal bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357002" comment="gzip is earlier than 0:1.3.3-12.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357005" comment="gzip is earlier than 0:1.3.3-15.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050358" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:358: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:358-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-358.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet.

An integer overflow flaw was found in PCRE, a Perl-compatible regular
expression library included within Exim.  A local user could create a
maliciously crafted regular expression in such as way that they could gain
the privileges of the 'exim' user.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2491 to this issue.  These
erratum packages change Exim to use the system PCRE library instead of the
internal one.  

These packages also fix a minor flaw where the Exim Monitor was incorrectly
computing free space on very large file systems.

Users should upgrade to these erratum packages and also ensure they have
updated the system PCRE library, for which erratum packages are available
seperately in RHSA-2005:761</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166332" id="166332">CAN-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358002" comment="exim is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050361" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:361: vixie-cron security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-361.html" />
          <reference source="CVE" ref_id="CVE-2005-1038" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1038.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is
possible for a local attacker to execute the crontab command in such a way
that they can view the contents of another user's crontab file. The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1038 to
this issue. 

Additionally, this update addresses the following issues:

o Fixed improper limits on filename and command line lengths 
o Improved PAM access control conforming to EAL certification requirements
o Improved reliability when running in a chroot environment
o Mail recipient name checking disabled by default, can be re-enabled 
o Added '-p' "permit all crontabs" option to disable crontab mode checking

All users of vixie-cron should upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1038.html">CVE-2005-1038</cve>
                <bugzilla href="http://bugzilla.redhat.com/147636" id="147636">cron fails to run user jobs and gives vague error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154920" id="154920">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159216" id="159216">vixie-cron updates for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163881" id="163881">Cron no longer allows read-only crontabs, enforces write access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163882" id="163882">cron fails with pam_access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163885" id="163885">crontab truncates file names greater than 100 characters.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163888" id="163888">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163889" id="163889">[PATCH] List corruption when items are removed from /etc/cron.d</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361002" comment="vixie-cron is earlier than 4:4.1-36.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050365" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:365: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:365-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-365.html" />
          <reference source="CVE" ref_id="CVE-2005-0965" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0965.html" />
          <reference source="CVE" ref_id="CVE-2005-0966" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0966.html" />
          <reference source="CVE" ref_id="CVE-2005-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0967.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

A buffer overflow bug was found in the way gaim escapes HTML. It is
possible that a remote attacker could send a specially crafted message to a
Gaim client, causing it to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0965 to this issue.

A bug was found in several of gaim's IRC processing functions. These
functions fail to properly remove various markup tags within an IRC
message. It is possible that a remote attacker could send a specially
crafted message to a Gaim client connected to an IRC server, causing it to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0966 to this issue.

A bug was found in gaim's Jabber message parser. It is possible for a
remote Jabber user to send a specially crafted message to a Gaim client,
causing it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0967 to this issue.

In addition to these denial of service issues, multiple minor upstream
bugfixes are included in this update.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.2.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-12" />
        <updated date="2005-04-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0965.html">CVE-2005-0965</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0966.html">CVE-2005-0966</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0967.html">CVE-2005-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/153311" id="153311">CAN-2005-0965 Gaim remote DoS issues (CAN-2005-0966)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153761" id="153761">CAN-2005-0967 jabber DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365002" comment="gaim is earlier than 1:1.2.1-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365005" comment="gaim is earlier than 1:1.2.1-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050366" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:366: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:366-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-366.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0207" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0207.html" />
          <reference source="CVE" ref_id="CVE-2005-0210" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0210.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0400" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0400.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0529" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0529.html" />
          <reference source="CVE" ref_id="CVE-2005-0530" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0530.html" />
          <reference source="CVE" ref_id="CVE-2005-0531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0531.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
          <reference source="CVE" ref_id="CVE-2005-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0767.html" />
          <reference source="CVE" ref_id="CVE-2005-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0815.html" />
          <reference source="CVE" ref_id="CVE-2005-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0839.html" />
          <reference source="CVE" ref_id="CVE-2005-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0867.html" />
          <reference source="CVE" ref_id="CVE-2005-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0977.html" />
          <reference source="CVE" ref_id="CVE-2005-1041" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1041.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw in the fib_seq_start function was discovered. A local user could use
this flaw to cause a denial of service (system crash) via /proc/net/route.
(CAN-2005-1041)

A flaw in the tmpfs file system was discovered. A local user could use this
flaw to cause a denial of service (system crash). (CAN-2005-0977)

An integer overflow flaw was found when writing to a sysfs file. A local
user could use this flaw to overwrite kernel memory, causing a denial of
service (system crash) or arbitrary code execution. (CAN-2005-0867)

Keith Owens reported a flaw in the Itanium unw_unwind_to_user function. A
local user could use this flaw to cause a denial of service (system crash)
on Itanium architectures. (CAN-2005-0135)

A flaw in the NFS client O_DIRECT error case handling was discovered. A
local user could use this flaw to cause a denial of service (system crash).
(CAN-2005-0207)

A small memory leak when defragmenting local packets was discovered that
affected the Linux 2.6 kernel netfilter subsystem.  A local user could send
a large number of carefully crafted fragments leading to memory exhaustion
(CAN-2005-0210)

A flaw was discovered in the Linux PPP driver. On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw was discovered in the ext2 file system code. When a new directory is
created, the ext2 block written to disk is not initialized, which could
lead to an information leak if a disk image is made available to
unprivileged users. (CAN-2005-0400)

A flaw in fragment queuing was discovered that affected the Linux kernel
netfilter subsystem. On systems configured to filter or process network
packets (e.g. firewalling), a remote attacker could send a carefully
crafted set of fragmented packets to a machine and cause a denial of
service (system crash). In order to sucessfully exploit this flaw, the
attacker would need to know or guess some aspects of the firewall ruleset
on the target system. (CAN-2005-0449)

A number of flaws were found in the Linux 2.6 kernel. A local user could
use these flaws to read kernel memory or cause a denial of service (crash).
(CAN-2005-0529, CAN-2005-0530, CAN-2005-0531)

An integer overflow in sys_epoll_wait in eventpoll.c was discovered. A
local user could use this flaw to overwrite low kernel memory. This memory
is usually unused, not usually resulting in a security consequence.
(CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered. A local
user could potentially use this flaw to cause a denial of service (crash).
(CAN-2005-0749)

A flaw was discovered in the bluetooth driver system. On systems where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

A race condition was discovered that affected the Radeon DRI driver. A
local user who has DRI privileges on a Radeon graphics card may be able to
use this flaw to gain root privileges. (CAN-2005-0767)

Multiple range checking flaws were discovered in the iso9660 file system
handler. An attacker could create a malicious file system image which would
cause a denial or service or potentially execute arbitrary code if mounted.
(CAN-2005-0815)

A flaw was discovered when setting line discipline on a serial tty. A local
user may be able to use this flaw to inject mouse movements or keystrokes
when another user is logged in. (CAN-2005-0839)

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.

Please note that</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0207.html">CVE-2005-0207</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0210.html">CVE-2005-0210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0400.html">CVE-2005-0400</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0529.html">CVE-2005-0529</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0530.html">CVE-2005-0530</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0531.html">CVE-2005-0531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0767.html">CVE-2005-0767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0815.html">CVE-2005-0815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0839.html">CVE-2005-0839</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0867.html">CVE-2005-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0977.html">CVE-2005-0977</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1041.html">CVE-2005-1041</cve>
                <bugzilla href="http://bugzilla.redhat.com/147468" id="147468">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148868" id="148868">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148878" id="148878">CAN-2005-0207 nfs client O_DIRECT oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149466" id="149466">CAN-2005-0529 Sign handling issues on v2.6 (CAN-2005-0530 CAN-2005-0531)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149589" id="149589">CAN-2005-0209 netfilter SKB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151240" id="151240">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151249" id="151249">CAN-2005-0736 epoll overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151902" id="151902">CAN-2005-0767 drm race in radeon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152177" id="152177">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152399" id="152399">CAN-2005-0400 ext2 mkdir() directory entry random kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152405" id="152405">CAN-2005-0815 isofs range checking flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152410" id="152410">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152417" id="152417">CAN-2005-0839 N_MOUSE line discipline flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152561" id="152561">CAN-2005-0977 tmpfs truncate bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154219" id="154219">CAN-2005-0867 sysfs signedness problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154551" id="154551">CAN-2005-1041 crash while reading /proc/net/route</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366002" comment="kernel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366006" comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366004" comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366008" comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050373" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:373: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-373.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management.

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet which will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc which can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally the following bugs have been fixed:
 - snmpwalk no longer hangs when a non-existant pid is listed. 
 - snmpd no longer segfaults due to incorrect handling of lmSensors. 
 - an incorrect assignment leading to invalid values in ASN mibs has been
   fixed.
 - on systems running a 64-bit kernel, the values in /proc/net/dev no 
   longer become too large to fit in a 32-bit object. 
 - the net-snmp-devel packages correctly depend on elfutils-libelf-devel.
 - large file systems are correctly handled
 - snmp daemon now reports gigabit Ethernet speeds correctly
 - fixed consistency between IP adresses and hostnames in configuration file

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/130252" id="130252">net-snmp-devel should depend on elfutils-libelf-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152448" id="152448">snmpd.conf hostname vs. IP inconsistancy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162907" id="162907">CAN-2005-2177 net-snmp denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164639" id="164639">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373004" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373010" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373008" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373006" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373002" comment="net-snmp is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050375" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:375: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:375-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-375.html" />
          <reference source="CVE" ref_id="CVE-2005-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0941.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap based buffer overflow bug was found in the OpenOffice.org DOC file
processor. An attacker could create a carefully crafted DOC file in such a
way that it could cause OpenOffice.org to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0941 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0941.html">CVE-2005-0941</cve>
                <bugzilla href="http://bugzilla.redhat.com/154540" id="154540">CAN-2005-0941 openoffice.org heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375006" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375002" comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375004" comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375011" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375009" comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375012" comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375010" comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050377" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:377: sharutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-377.html" />
          <reference source="CVE" ref_id="CVE-2004-1772" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1772.html" />
          <reference source="CVE" ref_id="CVE-2004-1773" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1773.html" />
          <reference source="CVE" ref_id="CVE-2005-0990" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0990.html" />
    
    <description>The sharutils package contains a set of tools for encoding and decoding
packages of files in binary or text format.

A stack based overflow bug was found in the way shar handles the -o option.
If a user can be tricked into running a specially crafted command, it could
lead to arbitrary code execution.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1772 to this issue.
Please note that this issue does not affect Red Hat Enterprise Linux 4.

Two buffer overflow bugs were found in sharutils. If an attacker can place
a malicious 'wc' command on a victim's machine, or trick a victim into
running a specially crafted command, it could lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1773 to this issue.

A bug was found in the way unshar creates temporary files. A local user
could use symlinks to overwrite arbitrary files the victim running unshar
has write access to. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0990 to this issue.

All users of sharutils should upgrade to this updated package, which
includes backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1772.html">CVE-2004-1772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1773.html">CVE-2004-1773</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0990.html">CVE-2005-0990</cve>
                <bugzilla href="http://bugzilla.redhat.com/152571" id="152571">CAN-2004-1772 buffer overflow with -o option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152573" id="152573">CAN-2004-1773 Buffer overflows in unshar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154049" id="154049">CAN-2005-0990 insecure temp file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377002" comment="sharutils is earlier than 0:4.2.1-16.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377005" comment="sharutils is earlier than 0:4.2.1-22.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050378" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:378: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:378-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-378.html" />
          <reference source="CVE" ref_id="CVE-2005-1111" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1111.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

A race condition bug was found in cpio. It is possible for a local
malicious user to modify the permissions of a local file if they have write
access to a directory in which a cpio archive is being extracted. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1111 to this issue.

Additionally, this update adds cpio support for archives larger than 2GB.
However, the size of individual files within an archive is limited to 4GB.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1111.html">CVE-2005-1111</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154507" id="154507">511278 - needs fix for RHEL 4 on cpio bugzilla 105617</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155749" id="155749">CVE-2005-1111 Race condition in cpio</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378002" comment="cpio is earlier than 0:2.5-4.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378005" comment="cpio is earlier than 0:2.5-8.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050381" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:381: nasm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:381-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-381.html" />
          <reference source="CVE" ref_id="CVE-2004-1287" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1287.html" />
          <reference source="CVE" ref_id="CVE-2005-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1194.html" />
    
    <description>NASM is an 80x86 assembler.

Two stack based buffer overflow bugs have been found in nasm. An attacker
could create an ASM file in such a way that when compiled by a victim,
could execute arbitrary code on their machine. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1287
and CAN-2005-1194 to these issues.

All users of nasm are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1287.html">CVE-2004-1287</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1194.html">CVE-2005-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/143081" id="143081">CAN-2004-1287 Bernstein class reports buffer overflow in nasm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152962" id="152962">CAN-2005-1194 Buffer overflow in the ieee_putascii() function</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381004" comment="nasm-doc is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381002" comment="nasm is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381006" comment="nasm-rdoff is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381010" comment="nasm-doc is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381009" comment="nasm is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381011" comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050383" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:383: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:383-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-383.html" />
          <reference source="CVE" ref_id="CVE-2005-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0752.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1158.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Vladimir V. Perepelitsa discovered a bug in the way Firefox handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Omar Khan discovered a bug in the way Firefox processes the PLUGINSPAGE
tag. It is possible for a malicious web page to trick a user into pressing
the "manual install" button for an unknown plugin leading to arbitrary
javascript code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0752 to this issue.

Doron Rosenberg discovered a bug in the way Firefox displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1153 to this issue.

A bug was found in the way Firefox handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1154 to
this issue.

Michael Krax discovered a bug in the way Firefox handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1155 to this issue.

Michael Krax discovered a bug in the way Firefox installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and steal sensitive information.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2005-1156 and CAN-2005-1157 to these issues. 

Kohei Yoshino discovered a bug in the way Firefox opens links in its
sidebar. A malicious web page could construct a link in such a way that,
when clicked on, could execute arbitrary javascript with elevated
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1158 to this issue.

A bug was found in the way Firefox validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1159 to this issue.

A bug was found in the way the Firefox privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1160 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.3 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-21" />
        <updated date="2005-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0752.html">CVE-2005-0752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1158.html">CVE-2005-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155114" id="155114">CAN-2005-0752 Multiple firefox issues. (CAN-2005-0989)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050383002" comment="firefox is earlier than 0:1.0.3-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050384" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:384: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-384.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found with the way Mozilla displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0143 CAN-2005-0593)

A bug was found in the way Mozilla handles synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

Several bugs were found with the way Mozilla handles temporary files. A
local user could view sensitive temporary information or delete arbitrary
files. (CAN-2005-0142 CAN-2005-0578)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

Several bugs were found in the way Mozilla displays alert dialogs. It is
possible for a malicious webserver or website to trick a user into thinking
the dialog window is being generated from a trusted site. (CAN-2005-0586
CAN-2005-0591 CAN-2005-0585 CAN-2005-0590 CAN-2005-0584)

A bug was found in the Mozilla javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed,
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Mozilla allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527)

A bug was found in the way Mozilla handles anonymous functions during
regular expression string replacement. It is possible for a malicious web
page to capture a random block of browser memory. (CAN-2005-0989)

A bug was found in the way Mozilla displays pop-up windows. If a user
choses to open a pop-up window whose URL is malicious javascript, the
script will be executed with elevated privileges. (CAN-2005-1153)

A bug was found in the way Mozilla installed search plugins. If a user
chooses to install a search plugin from a malicious site, the new plugin
could silently overwrite an existing plugin. This could allow the malicious
plugin to execute arbitrary code and stealm sensitive information.
(CAN-2005-1156 CAN-2005-1157)

Several bugs were found in the Mozilla javascript engine. A malicious web
page could leverage these issues to execute javascript with elevated
privileges or steal sensitive information. (CAN-2005-1154 CAN-2005-1155
CAN-2005-1159 CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/142390" id="142390">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144080" id="144080">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145606" id="145606">CAN-2005-0142 Opened attachments are temporarily saved world-readable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145607" id="145607">CAN-2005-0143 Secure site lock can be spoofed with a binary download</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145613" id="145613">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151722" id="151722">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152580" id="152580">CAN-2005-0578 Mozilla issues (CAN-2005-0232 CAN-2005-0527 CAN-2005-0231 CAN-2005-0584 CAN-2005-0585 CAN-2005-0586 CAN-2005-0588 CAN-2005-0590 CAN-2005-0591 CAN-2005-0593)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155117" id="155117">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384014" comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384016" comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384002" comment="mozilla is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384004" comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384012" comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384008" comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050386" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:386: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:386-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-386.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Vladimir V. Perepelitsa discovered a bug in the way Mozilla handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Doron Rosenberg discovered a bug in the way Mozilla displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges.
(CAN-2005-1153)

A bug was found in the way Mozilla handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. (CAN-2005-1154)

Michael Krax discovered a bug in the way Mozilla handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges.
(CAN-2005-1155)

Michael Krax discovered a bug in the way Mozilla installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and stealm sensitive
information. (CAN-2005-1156 CAN-2005-1157)

A bug was found in the way Mozilla validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Mozilla privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. (CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155116" id="155116">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386014" comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386016" comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386002" comment="mozilla is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386004" comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386012" comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386008" comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386022" comment="devhelp is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050387" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:387: cvs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:387-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-387.html" />
          <reference source="CVE" ref_id="CVE-2005-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0753.html" />
    
    <description>CVS (Concurrent Version System) is a version control system.

A buffer overflow bug was found in the way the CVS client processes version
and author information. If a user can be tricked into connecting to a
malicious CVS server, an attacker could execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0753 to this issue.

Additionally, a bug was found in which CVS freed an invalid pointer.
However, this issue does not appear to be exploitable.

All users of cvs should upgrade to this updated package, which includes a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0753.html">CVE-2005-0753</cve>
                <bugzilla href="http://bugzilla.redhat.com/155029" id="155029">CAN-2005-0753 multiple issues in cvs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387002" comment="cvs is earlier than 0:1.11.2-27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387005" comment="cvs is earlier than 0:1.11.17-7.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050392" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:392: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:392-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-392.html" />
          <reference source="CVE" ref_id="CVE-2005-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0755.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes RAM files.
An attacker could create a specially crafted RAM file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0755 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.4 and is not vulnerable to this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-20" />
        <updated date="2005-04-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0755.html">CVE-2005-0755</cve>
                <bugzilla href="http://bugzilla.redhat.com/155386" id="155386">CAN-2005-0755 HelixPlayer buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050392002" comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050393" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:393: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:393-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-393.html" />
          <reference source="CVE" ref_id="CVE-2005-1046" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1046.html" />
    
    <description>KDE is a graphical desktop environment for the X Window System. Konqueror
is the file manager for the K Desktop Environment. 

A source code audit performed by the KDE security team discovered several
vulnerabilities in the PCX and other image file format readers.

A buffer overflow was found in the kimgio library for KDE 3.4.0.  An
attacker could create a carefully crafted PCX image in such a way that it
would cause kimgio to execute arbitrary code when processing the image. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1046 to this issue.

All users of kdelibs should upgrade to these updated packages, which
contain a backported security patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1046.html">CVE-2005-1046</cve>
                <bugzilla href="http://bugzilla.redhat.com/152092" id="152092">CAN-2005-1046 PCX file integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393002" comment="kdelibs is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393004" comment="kdelibs-devel is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050395" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:395: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-395.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management. 

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet that will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc that can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally, the following bugs have been fixed:
- The lmSensors are correctly recognized, snmp deamon no longer segfaults
- The larger swap partition sizes are correctly reported 
- Querying hrSWInstalledLastUpdateTime no longer crashes the snmp deamon
- Fixed error building ASN.1 representation
- The 64-bit network counters correctly wrap
- Large file systems are correctly handled
- Snmptrapd initscript correctly reads options from its configuration 
  file /etc/snmp/snmptrapd.options 
- Snmp deamon no longer crashes when restarted using the agentX 
  protocol
- snmp daemon now reports gigabit Ethernet speeds correctly
- MAC adresses are shown when requested instead of IP adresses

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/150084" id="150084">snmpd dies when getting enterprises.ucdavis.memory.memTotalSwap.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150199" id="150199">snmpd exits without a diagnostic: SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154798" id="154798">/etc/init.d/snmptrapd wrong order in setting variables...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155038" id="155038">x86_64: net-snmp dies when querying hrSWInstalledLastUpdateTime</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158769" id="158769">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163688" id="163688">CAN-2005-2177 net-snmp denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395004" comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395010" comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395008" comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395006" comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395002" comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050396" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:396: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:396-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-396.html" />
          <reference source="CVE" ref_id="CVE-2005-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2495.html" />
    
    <description>X.org is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow bugs were found in the way X.org parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue. 

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-13" />
        <updated date="2005-09-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2495.html">CVE-2005-2495</cve>
                <bugzilla href="http://bugzilla.redhat.com/166856" id="166856">CAN-2005-2495 multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396034" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396022" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396020" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396028" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396032" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396024" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396030" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396026" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050397" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:397: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-397.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
          <reference source="CVE" ref_id="CVE-2005-0806" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0806.html" />
    
    <description>Evolution is a GNOME-based collection of personal information management
(PIM) tools.

A bug was found in the way Evolution displays mail messages. It is possible
that an attacker could create a specially crafted mail message that when
opened by a victim causes Evolution to stop responding. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0806 to this issue.

A bug was also found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue.  On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default.  Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

All users of evolution should upgrade to these updated packages, which
include backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0806.html">CVE-2005-0806</cve>
                <bugzilla href="http://bugzilla.redhat.com/155375" id="155375">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155377" id="155377">CAN-2005-0806 DoS from mail message</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397002" comment="evolution is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397004" comment="evolution-devel is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050405" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:405: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:405-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-405.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way that it could execute arbitrary instructions when processed by PHP.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
 to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- The security fixes in RHSA-2004-687 to the "unserializer" code introduced
some performance issues.

- In the gd extension, the "imagecopymerge" function did not correctly
handle transparency.  The original image was being obscured in the
resultant image.

- In the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/145436" id="145436">PHP pages slow, HTTPD eating cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147808" id="147808">php curl open_basedir bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149873" id="149873">make PHP oci8 driver support Oracle Instant Client RPM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149946" id="149946">PHP GD ImageCopyMerge broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405014" comment="php-odbc is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405010" comment="php-mysql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405002" comment="php is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405012" comment="php-pgsql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405004" comment="php-devel is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405006" comment="php-imap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405008" comment="php-ldap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050406" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:406: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-406.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way it could execute arbitrary instructions when processed by PHP. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- some performance issues in the unserialize() function have been fixed

- the behaviour of the interpreter when handling integer overflow during
conversion of a floating variable to an integer has been reverted to match
the behaviour used upstream; the integer will now be wrapped rather than
truncated

- a fix for the virtual() function in the Apache httpd module which would
flush the response prematurely

- the hard-coded default "safe mode" setting is now "disabled" rather than
"enabled"; to match the default /etc/php.ini setting

- in the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/153108" id="153108">Error in configure prevents php SRPM rebuild on x86_64 w/ mssql module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406028" comment="php-gd is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406016" comment="php-odbc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406012" comment="php-mysql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406002" comment="php is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406022" comment="php-xmlrpc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406024" comment="php-mbstring is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406014" comment="php-pgsql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406004" comment="php-devel is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406026" comment="php-ncurses is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406018" comment="php-snmp is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406008" comment="php-imap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406006" comment="php-pear is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406020" comment="php-domxml is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406010" comment="php-ldap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050408" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:408: cyrus-imapd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:408-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-408.html" />
          <reference source="CVE" ref_id="CVE-2005-0546" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0546.html" />
    
    <description>The cyrus-imapd package contains the core of the Cyrus IMAP server.

Several buffer overflow bugs were found in cyrus-imapd. It is possible that
an authenticated malicious user could cause the imap server to crash.
Additionally, a peer news admin could potentially execute arbitrary code on
the imap server when news is received using the fetchnews command. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages, which
contain cyrus-imapd version 2.2.12 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0546.html">CVE-2005-0546</cve>
                <bugzilla href="http://bugzilla.redhat.com/149869" id="149869">CAN-2005-0546 multiple buffer overflows in cyrus-imapd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408006" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408007" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408004" comment="cyrus-imapd-murder is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408005" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408002" comment="cyrus-imapd is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408003" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408012" comment="cyrus-imapd-utils is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408013" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408008" comment="cyrus-imapd-devel is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408009" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408010" comment="perl-Cyrus is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408011" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050410" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:410: gftp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-410.html" />
          <reference source="CVE" ref_id="CVE-2005-0372" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0372.html" />
    
    <description>gFTP is a multi-threaded FTP client for the X Window System.

A directory traversal bug was found in gFTP. If a user can be tricked into
downloading a file from a malicious ftp server, it is possible to overwrite
arbitrary files owned by the victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0372 to
this issue.

Users of gftp should upgrade to this updated package, which contains a
backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0372.html">CVE-2005-0372</cve>
                <bugzilla href="http://bugzilla.redhat.com/149109" id="149109">CAN-2005-0372 directory traversal issue in gftp</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410002" comment="gftp is earlier than 1:2.0.14-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410005" comment="gftp is earlier than 1:2.0.17-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050412" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:412: openmotif security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:412-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-412.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.  

An integer overflow flaw was found in libXpm, which is used to decode XPM
(X PixMap) images.  A vulnerable version of this library was
found within OpenMotif.  An attacker could create a carefully crafted XPM
file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0605 to
this issue.

Users of OpenMotif are advised to upgrade to these erratum packages, which
contains a backported security patch to the embedded libXpm library.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/151641" id="151641">CAN-2005-0605 libxpm issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412002" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412006" comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412004" comment="openmotif is earlier than 0:2.2.3-5.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412009" comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412011" comment="openmotif-devel is earlier than 0:2.2.3-9.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412010" comment="openmotif is earlier than 0:2.2.3-9.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050413" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:413: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-413.html" />
          <reference source="CVE" ref_id="CVE-2005-1275" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1275.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A heap based buffer overflow bug was found in the way ImageMagick parses
PNM files. An attacker could execute arbitrary code on a victim's machine
if they were able to trick the victim into opening a specially crafted PNM
file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1275 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-25" />
        <updated date="2005-05-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1275.html">CVE-2005-1275</cve>
                <bugzilla href="http://bugzilla.redhat.com/155953" id="155953">CAN-2005-1275 ImageMagick PNM heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413004" comment="ImageMagick-devel is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413006" comment="ImageMagick-perl is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413002" comment="ImageMagick is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413008" comment="ImageMagick-c++ is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413017" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413014" comment="ImageMagick-devel is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413015" comment="ImageMagick-perl is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413013" comment="ImageMagick is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413016" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050415" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:415: squid security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:415-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-415.html" />
          <reference source="CVE" ref_id="CVE-1999-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-0710.html" />
          <reference source="CVE" ref_id="CVE-2005-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0626.html" />
          <reference source="CVE" ref_id="CVE-2005-0718" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0718.html" />
          <reference source="CVE" ref_id="CVE-2005-1345" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1345.html" />
          <reference source="CVE" ref_id="CVE-2005-1519" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1519.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
 
A race condition bug was found in the way Squid handles the now obsolete
Set-Cookie header. It is possible that Squid can leak Set-Cookie header
information to other clients connecting to Squid. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0626 to this issue. Please note that this issue only affected Red
Hat Enterprise Linux 4. 
 
A bug was found in the way Squid handles PUT and POST requests. It is
possible for an authorised remote user to cause a failed PUT or POST
request which can cause Squid to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0718 to
this issue.
 
A bug was found in the way Squid processes errors in the access control
list. It is possible that an error in the access control list could give
users more access than intended. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1345 to this issue.
 
A bug was found in the way Squid handles access to the cachemgr.cgi script. 
It is possible for an authorised remote user to bypass access control
lists with this flaw. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-1999-0710 to this issue.
 
A bug was found in the way Squid handles DNS replies.  If the port Squid
uses for DNS requests is not protected by a firewall it is possible for a
remote attacker to spoof DNS replies, possibly redirecting a user to
spoofed or malicious content. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1519 to this issue. 
 
Additionally this update fixes the following bugs:   
 - LDAP Authentication fails with an assertion error when using Red Hat
Enterprise Linux 4 
 
Users of Squid should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-14" />
        <updated date="2005-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-0710.html">CVE-1999-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0626.html">CVE-2005-0626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0718.html">CVE-2005-0718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1345.html">CVE-2005-1345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1519.html">CVE-2005-1519</cve>
                <bugzilla href="http://bugzilla.redhat.com/125007" id="125007">insecure permissions for squid.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150232" id="150232">CAN-2005-0626 Cookie leak in squid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150907" id="150907">LDAP Authentication fails with an assertion error.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151412" id="151412">CAN-2005-1345 Unexpected access control results on configuration errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151423" id="151423">CAN-2005-0718 Segmentation fault on failed PUT/POST request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156161" id="156161">CVE-1999-0710 cachemgr.cgi access control bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157455" id="157455">CAN-2005-1519 DNS lookups unreliable on untrusted networks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050415002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050415005" comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050417" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:417: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:417-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-417.html" />
          <reference source="CVE" ref_id="CVE-2005-1278" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1278.html" />
          <reference source="CVE" ref_id="CVE-2005-1279" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1279.html" />
          <reference source="CVE" ref_id="CVE-2005-1280" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1280.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

The tcpdump utility can now write a file larger than 2 GB. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1278.html">CVE-2005-1278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1279.html">CVE-2005-1279</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1280.html">CVE-2005-1280</cve>
                <bugzilla href="http://bugzilla.redhat.com/147840" id="147840">tcpdump can't write to a file greater than 2G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156040" id="156040">CAN-2005-1280 Multiple DoS issues in tcpdump (CAN-2005-1279 CAN-2005-1278)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417004" comment="libpcap is earlier than 14:0.8.3-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417002" comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417006" comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050420" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:420: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 1 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:420-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-420.html" />
          <reference source="CVE" ref_id="CVE-2005-0136" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0136.html" />
          <reference source="CVE" ref_id="CVE-2005-0209" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0209.html" />
          <reference source="CVE" ref_id="CVE-2005-0937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0937.html" />
          <reference source="CVE" ref_id="CVE-2005-1264" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1264.html" />
          <reference source="CVE" ref_id="CVE-2005-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3107.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the first regular kernel update to Red Hat Enterprise Linux 4.

A flaw affecting the auditing code was discovered.  On Itanium
architectures a local user could use this flaw to cause a denial of service
(crash).  This issue is rated as having important security impact
(CAN-2005-0136). 

A flaw was discovered in the servicing of a raw device ioctl.  A local user
who has access to raw devices could use this flaw to write to kernel memory
and cause a denial of service or potentially gain privileges.  This issue
is rated as having moderate security impact (CAN-2005-1264). 

A flaw in fragment forwarding was discovered that affected the netfilter
subsystem for certain network interface cards. A remote attacker could send
a set of bad fragments and cause a denial of service (system crash). Acenic
and SunGEM network interfaces were the only adapters affected, which are in
widespread use. (CAN-2005-0209)

A flaw in the futex functions was discovered affecting the Linux 2.6
kernel.  A local user could use this flaw to cause a denial of service
(system crash). (CAN-2005-0937)

New features introduced by this update include:
- Fixed TCP BIC congestion handling.
- Diskdump support for more controllers (megaraid, SATA)
- Device mapper multipath support
- AMD64 dual core support.
- Intel ICH7 hardware support.

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.

The following device drivers have been upgraded to new versions:
 ata_piix -------- 1.03
 bonding --------- 2.6.1
 e1000 ----------- 5.6.10.1-k2-NAPI
 e100 ------------ 3.3.6-k2-NAPI
 ibmveth --------- 1.03
 libata ---------- 1.02 to 1.10
 lpfc ------------ 0:8.0.16 to 0:8.0.16.6_x2
 megaraid_mbox --- 2.20.4.0 to 2.20.4.5
 megaraid_mm ----- 2.20.2.0-rh1 to 2.20.2.5
 sata_nv --------- 0.03 to 0.6
 sata_promise ---- 1.00 to 1.01
 sata_sil -------- 0.8
 sata_sis -------- 0.5
 sata_svw -------- 1.05
 sata_sx4 -------- 0.7
 sata_via -------- 1.0
 sata_vsc -------- 1.0
 tg3 ------------- 3.22-rh
 ipw2100 --------- 1.0.3
 ipw2200 --------- 1.0.0

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0136.html">CVE-2005-0136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0209.html">CVE-2005-0209</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0937.html">CVE-2005-0937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1264.html">CVE-2005-1264</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3107.html">CVE-2005-3107</cve>
                <bugzilla href="http://bugzilla.redhat.com/133590" id="133590">PTRACE_ATTACH race with real parent's wait calls can produced bogus wait returns</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134338" id="134338">Intolerable Disk I/O Performance under 64-bit VM: fix I/O buffers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137154" id="137154">"waitid(POSIX Interface)" cannot run properly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138563" id="138563">[PATCH] RHEL4 U1: EFI GPT: reduce alternate header probing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140083" id="140083">lx-choptp19 crashed running 2.4.21-20.EL.BZ131027.hotfixhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140383" id="140383">BLKFLSBUF ioctl can cause other reads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140472" id="140472">x86, x86_64 and IA64 scsi inquiry command hangs in wait_for_completion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141699" id="141699">FEAT: RHEL 4 U3: ia64 needs hint@pause in spinloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141983" id="141983">RHEL4 U2: DBS: quiet warning messages from cpufreq.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142167" id="142167">[RHEL4][Diskdump] smp_call_function issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142464" id="142464">[PATCH] "RPC: garbage, exit EIO" when using NFSv3 with Kerberos 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143073" id="143073">traced process cannot be killed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143472" id="143472">hugetlb mmap failed in compatibility mode in em64t</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143907" id="143907">ext2 and device dm-0 byond 2Terabyte causes /var/log/messages file size to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144741" id="144741">RHEL4 U1: ICH7 Support patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145424" id="145424">problems with ipsec from rhel3 to rhel4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146067" id="146067">[PATCH] Channel bonding driver configured in 802.3 ad mode causes kernel panic when shutdwon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146089" id="146089">20050115 ptrace/kill and ptrace/dump race fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146703" id="146703">NLM (NFSv3) problems when mounting with "sec=krb5"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146797" id="146797">SCTP memory consumption and system freezes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146911" id="146911">Thread suspension via async signal fails on rhel4-rc2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147832" id="147832">oom-killer triggered during Red Hat Cert</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150110" id="150110">chipset identifier for zx2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150151" id="150151">Lockd callbacks to NFS clients fail completely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151284" id="151284">mmap of file over NFS corrupts data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152101" id="152101">host panics when mounting nfs4 volumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152102" id="152102">host loses connection to nfs server when the server is solaris</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152557" id="152557">20050117 Oopsable NFS locking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154221" id="154221">Thread exits siliently via __RESTORE_ALL exeception for iret</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154639" id="154639">kernel thread current->mm dereference in grab_swap_token causes oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154972" id="154972">unexplained SIGSEGV death in SIGSEGV signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155283" id="155283">CAN-2005-0136 ptrace corner cases on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155765" id="155765">oops on 2.6.9-5.0.5.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156875" id="156875">libata - master supports lba48 but slave does not</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157450" id="157450">CAN-2005-1263 Linux kernel ELF core dump privilege elevation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420002" comment="kernel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420006" comment="kernel-doc is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420004" comment="kernel-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420010" comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420012" comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420008" comment="kernel-smp is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050421" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:421: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:421-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-421.html" />
          <reference source="CVE" ref_id="CVE-2005-1278" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1278.html" />
          <reference source="CVE" ref_id="CVE-2005-1279" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1279.html" />
          <reference source="CVE" ref_id="CVE-2005-1280" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1280.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

Additionally, the tcpdump utility can now write a file larger than 2 GB,
parse some new VLAN IDs, and parse messages on 64bit architectures. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1278.html">CVE-2005-1278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1279.html">CVE-2005-1279</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1280.html">CVE-2005-1280</cve>
                <bugzilla href="http://bugzilla.redhat.com/132781" id="132781">[RHEL3] tcpdump not decoding NFS traffic properly on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147840" id="147840">tcpdump can't write to a file greater than 2G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156040" id="156040">CAN-2005-1280 Multiple DoS issues in tcpdump (CAN-2005-1279 CAN-2005-1278)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421004" comment="libpcap is earlier than 14:0.7.2-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421002" comment="tcpdump is earlier than 14:3.7.2-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421006" comment="arpwatch is earlier than 14:2.1a11-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050427" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:427: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-427.html" />
          <reference source="CVE" ref_id="CVE-2005-1456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1456.html" />
          <reference source="CVE" ref_id="CVE-2005-1457" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1457.html" />
          <reference source="CVE" ref_id="CVE-2005-1458" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1458.html" />
          <reference source="CVE" ref_id="CVE-2005-1459" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1459.html" />
          <reference source="CVE" ref_id="CVE-2005-1460" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1460.html" />
          <reference source="CVE" ref_id="CVE-2005-1461" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1461.html" />
          <reference source="CVE" ref_id="CVE-2005-1462" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1462.html" />
          <reference source="CVE" ref_id="CVE-2005-1463" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1463.html" />
          <reference source="CVE" ref_id="CVE-2005-1464" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1464.html" />
          <reference source="CVE" ref_id="CVE-2005-1465" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1465.html" />
          <reference source="CVE" ref_id="CVE-2005-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1466.html" />
          <reference source="CVE" ref_id="CVE-2005-1467" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1467.html" />
          <reference source="CVE" ref_id="CVE-2005-1468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1468.html" />
          <reference source="CVE" ref_id="CVE-2005-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1469.html" />
          <reference source="CVE" ref_id="CVE-2005-1470" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1470.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-1456, CAN-2005-1457,
CAN-2005-1458, CAN-2005-1459, CAN-2005-1460, CAN-2005-1461, CAN-2005-1462,
CAN-2005-1463, CAN-2005-1464, CAN-2005-1465, CAN-2005-1466, CAN-2005-1467,
CAN-2005-1468, CAN-2005-1469, and CAN-2005-1470 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.11 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-24" />
        <updated date="2005-05-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1456.html">CVE-2005-1456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1457.html">CVE-2005-1457</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1458.html">CVE-2005-1458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1459.html">CVE-2005-1459</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1460.html">CVE-2005-1460</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1461.html">CVE-2005-1461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1462.html">CVE-2005-1462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1463.html">CVE-2005-1463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1464.html">CVE-2005-1464</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1465.html">CVE-2005-1465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1466.html">CVE-2005-1466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1467.html">CVE-2005-1467</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1468.html">CVE-2005-1468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1469.html">CVE-2005-1469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1470.html">CVE-2005-1470</cve>
                <bugzilla href="http://bugzilla.redhat.com/156911" id="156911">multiple ethereal security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427004" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427002" comment="ethereal is earlier than 0:0.10.11-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427008" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427007" comment="ethereal is earlier than 0:0.10.11-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050429" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:429: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-429.html" />
          <reference source="CVE" ref_id="CVE-2005-1261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1261.html" />
          <reference source="CVE" ref_id="CVE-2005-1262" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1262.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

A stack based buffer overflow bug was found in the way gaim processes a
message containing a URL. A remote attacker could send a carefully crafted
message resulting in the execution of arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1261 to this issue.

A bug was found in the way gaim handles malformed MSN messages. A remote
attacker could send a carefully crafted MSN message causing gaim to crash.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1262 to this issue.

Users of Gaim are advised to upgrade to this updated package which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1261.html">CVE-2005-1261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1262.html">CVE-2005-1262</cve>
                <bugzilla href="http://bugzilla.redhat.com/157017" id="157017">CAN-2005-1261 Gaim long url buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157202" id="157202">CAN-2005-1262 Gaim MSN DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050429002" comment="gaim is earlier than 1:1.2.1-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050429005" comment="gaim is earlier than 1:1.2.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050430" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:430: gnutls security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-430.html" />
          <reference source="CVE" ref_id="CVE-2005-1431" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1431.html" />
    
    <description>The GnuTLS library implements Secure Sockets Layer (SSL v3) and Transport
Layer Security (TLS v1) protocols.

A denial of service bug was found in the GnuTLS library versions prior to
1.0.25. A remote attacker could perform a carefully crafted TLS handshake
against a service that uses the GnuTLS library causing the service to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1431 to this issue.

All users of GnuTLS are advised to upgrade to these updated packages and to
restart any services which use GnuTLS.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1431.html">CVE-2005-1431</cve>
                <bugzilla href="http://bugzilla.redhat.com/156856" id="156856">CAN-2005-1431 gnutls record packet parsing DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050430004" comment="gnutls-devel is earlier than 0:1.0.20-3.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430005" comment="gnutls-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050430002" comment="gnutls is earlier than 0:1.0.20-3.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430003" comment="gnutls is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050433" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:433: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:433-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-433.html" />
          <reference source="CVE" ref_id="CVE-2005-1409" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1409.html" />
          <reference source="CVE" ref_id="CVE-2005-1410" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1410.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS) that supports almost all SQL constructs (including
transactions, subselects and user-defined types and functions).

The PostgreSQL community discovered two distinct errors in initial system
catalog entries that could allow authorized database users to crash the
database and possibly escalate their privileges.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-1409 and CAN-2005-1410 to these issues.

Although installing this update will protect new (freshly initdb'd)
database installations from these errors, administrators MUST TAKE MANUAL
ACTION to repair the errors in pre-existing databases.  The appropriate
procedures are explained at
http://www.postgresql.org/docs/8.0/static/release-7-4-8.html
for Red Hat Enterprise Linux 4 users, or
http://www.postgresql.org/docs/8.0/static/release-7-3-10.html
for Red Hat Enterprise Linux 3 users.

This update corrects several problems that might occur while trying to
upgrade a Red Hat Enterprise Linux 3 installation (containing rh-postgresql
packages) to Red Hat Enterprise Linux 4 (containing postgresql packages).
These updated packages correctly supersede the rh-postgresql packages.

The original release of Red Hat Enterprise Linux 4 failed to initialize the
database correctly if started for the first time with SELinux in
enforcement mode. This update corrects that problem.  

If you already have a nonfunctional database in place, shut down the
postgresql service if running, install this update, then do "sudo rm -rf
/var/lib/pgsql/data" before restarting the postgresql service.

This update also solves the problem that the PostgreSQL server might fail
to restart after a system reboot, due to a stale lockfile.

This update also corrects a problem with wrong error messages in libpq,
the postgresql client library.  The library would formerly report kernel
error messages incorrectly when the locale setting was not C.

This update also includes fixes for several other errors, including two
race conditions that could result in apparent data inconsistency or actual
data loss.

All users of PostgreSQL are advised to upgrade to these updated packages
and to apply the recommended manual corrections to existing databases.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1409.html">CVE-2005-1409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1410.html">CVE-2005-1410</cve>
                <bugzilla href="http://bugzilla.redhat.com/149237" id="149237">selinux &lt;&lt;EOF bug breaks PostgreSQL too</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151421" id="151421">PostgreSQL server does not start after crash because wrong PID file location</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151911" id="151911">upgrade from rhel-3 rh-postgresql to rhel-4 postgresql removes user "postgres"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156726" id="156726">CAN-2005-1409 Multiple postgresql issues (CAN-2005-1410)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433020" comment="rh-postgresql-jdbc is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433008" comment="rh-postgresql-docs is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433010" comment="rh-postgresql-contrib is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433002" comment="rh-postgresql is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433018" comment="rh-postgresql-python is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433014" comment="rh-postgresql-pl is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433012" comment="rh-postgresql-devel is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433022" comment="rh-postgresql-test is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433016" comment="rh-postgresql-tcl is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433006" comment="rh-postgresql-server is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433004" comment="rh-postgresql-libs is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433043" comment="postgresql-jdbc is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433031" comment="postgresql-docs is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433035" comment="postgresql-devel is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433045" comment="postgresql-test is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433033" comment="postgresql-contrib is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433027" comment="postgresql-libs is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433039" comment="postgresql-tcl is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433025" comment="postgresql is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433041" comment="postgresql-python is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433037" comment="postgresql-pl is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433029" comment="postgresql-server is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050434" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:434: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-434.html" />
          <reference source="CVE" ref_id="CVE-2005-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1476.html" />
          <reference source="CVE" ref_id="CVE-2005-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1477.html" />
          <reference source="CVE" ref_id="CVE-2005-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1531.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several bugs were found in the way Firefox executes javascript code.
Javascript executed from a web page should run with a restricted access
level, preventing dangerous actions. It is possible that a malicious web
page could execute javascript code with elevated privileges, allowing
access to protected data and functions. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-1476,
CAN-2005-1477, CAN-2005-1531, and CAN-2005-1532 to these issues.

Please note that the effects of CAN-2005-1477 are mitigated by the default
setup, which allows only the Mozilla Update site to attempt installation of
Firefox extensions. The Mozilla Update site has been modified to prevent
this attack from working. If other URLs have been manually added to the
whitelist, it may be possible to execute this attack.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.4 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-23" />
        <updated date="2005-05-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1476.html">CVE-2005-1476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1477.html">CVE-2005-1477</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1531.html">CVE-2005-1531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
                <bugzilla href="http://bugzilla.redhat.com/157347" id="157347">CAN-2005-1476 Multiple Firefox issues (CAN-2005-1477 CAN-2005-1531 CAN-2005-1532)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050434002" comment="firefox is earlier than 0:1.0.4-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050435" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:435: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:435-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-435.html" />
          <reference source="CVE" ref_id="CVE-2005-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1476.html" />
          <reference source="CVE" ref_id="CVE-2005-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1477.html" />
          <reference source="CVE" ref_id="CVE-2005-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1531.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found in the way Mozilla executes javascript code.
Javascript executed from a web page should run with a restricted access
level, preventing dangerous actions. It is possible that a malicious web
page could execute javascript code with elevated privileges, allowing
access to protected data and functions. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-1476,
CAN-2005-1477, CAN-2005-1531, and CAN-2005-1532 to these issues.

Users of Mozilla are advised to upgrade to this updated package, which
contains Mozilla version 1.7.8 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-24" />
        <updated date="2005-05-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1476.html">CVE-2005-1476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1477.html">CVE-2005-1477</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1531.html">CVE-2005-1531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
                <bugzilla href="http://bugzilla.redhat.com/157349" id="157349">CAN-2005-1476 Multiple Mozilla issues (CAN-2005-1477 CAN-2005-1531 CAN-2005-1532)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158533" id="158533">devhelp not updated for new mozilla</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435010" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435012" comment="mozilla-mail is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435004" comment="mozilla-chat is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435020" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435002" comment="mozilla is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435016" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435014" comment="mozilla-nspr is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435008" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435006" comment="mozilla-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435018" comment="mozilla-nss is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435027" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435028" comment="mozilla-mail is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435024" comment="mozilla-chat is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435032" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435023" comment="mozilla is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435030" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435029" comment="mozilla-nspr is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435026" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435025" comment="mozilla-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435031" comment="mozilla-nss is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435033" comment="devhelp is earlier than 0:0.9.2-2.4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050472" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:472: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-472.html" />
          <reference source="CVE" ref_id="CVE-2004-0491" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0491.html" />
          <reference source="CVE" ref_id="CVE-2005-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0176.html" />
          <reference source="CVE" ref_id="CVE-2005-1263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1263.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the three security issues
described below as well as an important fix for a problem that could
lead to data corruption on x86-architecture SMP systems with greater
than 4GB of memory through heavy usage of multi-threaded applications.

A flaw between execve() syscall handling and core dumping of ELF-format
executables allowed local unprivileged users to cause a denial of
service (system crash) or possibly gain privileges.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-1263
to this issue.

A flaw in shared memory locking allowed local unprivileged users to lock
and unlock regions of shared memory segments they did not own (CAN-2005-0176).

A flaw in the locking of SysV IPC shared memory regions allowed local
unprivileged users to bypass their RLIMIT_MEMLOCK resource limit
(CAN-2004-0491).

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.

Please also consult the RHEL3 Update 5 advisory RHSA-2005:294 for the
complete list of features added and bugs fixed in U5, which was released
only a week prior to this security update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-25" />
        <updated date="2005-05-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0491.html">CVE-2004-0491</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0176.html">CVE-2005-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1263.html">CVE-2005-1263</cve>
                <bugzilla href="http://bugzilla.redhat.com/126411" id="126411">CVE-2004-0491 mlock accounting issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141394" id="141394">Memory corruption with kernel 2.4.21-27.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141905" id="141905">kernel 2.4.21-25.ELsmp panic (kscand)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142802" id="142802">CVE-2005-0176 unlock someone elses ipc memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149087" id="149087">Kernel panic regression in 2.4.21-27.0.2.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151865" id="151865">Page corruption in U5 Beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156023" id="156023">Memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157451" id="157451">CVE-2005-1263 Linux kernel ELF core dump crash vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472004" comment="kernel-source is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472002" comment="kernel is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472006" comment="kernel-doc is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472018" comment="kernel-hugemem is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472008" comment="kernel-BOOT is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472010" comment="kernel-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472014" comment="kernel-smp is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050474" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:474: bzip2 security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:474-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-474.html" />
          <reference source="CVE" ref_id="CVE-2005-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0758.html" />
          <reference source="CVE" ref_id="CVE-2005-0953" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0953.html" />
          <reference source="CVE" ref_id="CVE-2005-1260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1260.html" />
    
    <description>Bzip2 is a data compressor.

A bug was found in the way bzgrep processes file names. If a user can be
tricked into running bzgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running bzgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CVE-2005-0758 to this issue.

A bug was found in the way bzip2 modifies file permissions during
decompression. If an attacker has write access to the directory into which
bzip2 is decompressing files, it is possible for them to modify permissions
on files owned by the user running bzip2 (CVE-2005-0953).

A bug was found in the way bzip2 decompresses files. It is possible for an
attacker to create a specially crafted bzip2 file which will cause bzip2 to
cause a denial of service (by filling disk space) if decompressed by a
victim (CVE-2005-1260).

Users of Bzip2 should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-06-16" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0758.html">CVE-2005-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0953.html">CVE-2005-0953</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1260.html">CVE-2005-1260</cve>
                <bugzilla href="http://bugzilla.redhat.com/155742" id="155742">CAN-2005-0953 bzip2 race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157548" id="157548">CAN-2005-1260 bzip2 decompression bomb (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159816" id="159816">CVE-2005-0758 bzgrep has security issue in sed usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474004" comment="bzip2-devel is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474005" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474006" comment="bzip2-libs is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474007" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474002" comment="bzip2 is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474003" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474010" comment="bzip2-devel is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474005" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474011" comment="bzip2-libs is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474007" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474009" comment="bzip2 is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474003" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050476" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:476: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:476-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-476.html" />
          <reference source="CVE" ref_id="CVE-2004-0975" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0975.html" />
          <reference source="CVE" ref_id="CVE-2005-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0109.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

Colin Percival reported a cache timing attack that could allow a malicious
local user to gain portions of cryptographic keys.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) assigned the name
CAN-2005-0109 to the issue.  The OpenSSL library has been patched to add a
new fixed-window mod_exp implementation as default for RSA, DSA, and DH
private-key operations.  This patch is designed to mitigate cache timing
and potentially related attacks.

A flaw was found in the way the der_chop script creates temporary files. It
is possible that a malicious local user could cause der_chop to overwrite
files (CAN-2004-0975).  The der_chop script was deprecated and has been
removed from these updated packages.  Red Hat Enterprise Linux 4 did not
ship der_chop and is therefore not vulnerable to this issue.

Users are advised to update to these erratum packages which contain patches
to correct these issues.

Please note: After installing this update, users are advised to either
restart all services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0975.html">CVE-2004-0975</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0109.html">CVE-2005-0109</cve>
                <bugzilla href="http://bugzilla.redhat.com/136302" id="136302">CAN-2004-0975 temporary file vulnerabilities in der_chop script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140061" id="140061">CAN-2004-0975 temporary file vulnerabilities in der_chop script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157631" id="157631">CAN-2005-0109 timing attack on OpenSSL with HT</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476002" comment="openssl096b is earlier than 0:0.9.6b-16.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476004" comment="openssl is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476008" comment="openssl-perl is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476006" comment="openssl-devel is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476011" comment="openssl096b is earlier than 0:0.9.6b-22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476012" comment="openssl is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476014" comment="openssl-perl is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476013" comment="openssl-devel is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050480" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:480: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-480.html" />
          <reference source="CVE" ref_id="CVE-2005-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1739.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A denial of service bug was found in the way ImageMagick parses XWD files.
A user or program executing ImageMagick to process a malicious XWD file can
cause ImageMagick to enter an infinite loop causing a denial of service
condition. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-1739 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-02" />
        <updated date="2005-06-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1739.html">CVE-2005-1739</cve>
                <bugzilla href="http://bugzilla.redhat.com/158790" id="158790">CAN-2005-1739 ImageMagick XWD denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480004" comment="ImageMagick-devel is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480006" comment="ImageMagick-perl is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480002" comment="ImageMagick is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480008" comment="ImageMagick-c++ is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480017" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480014" comment="ImageMagick-devel is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480015" comment="ImageMagick-perl is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480013" comment="ImageMagick is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480016" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050498" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:498: spamassassin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:498-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-498.html" />
          <reference source="CVE" ref_id="CVE-2005-1266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1266.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug has been found in SpamAssassin.  An attacker could
construct a message in such a way that would cause SpamAssassin to consume
CPU resources.  If a number of these messages were sent it could lead to a
denial of service, potentially  preventing the delivery or filtering of
email. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1266 to this issue.

SpamAssassin version 3.0.4 additionally solves a number of bugs including:
- #156390 Spamassassin consumes too much memory during learning
- #155423 URI blacklist spam bypass
- #147464 Users may now disable subject rewriting
- Smarter default Bayes scores
- Numerous other bug fixes that improve spam filter accuracy and safety

For full details, please refer to the change details of 3.0.2, 3.0.3, and
3.0.4 in SpamAssassin's online documentation at the following address:
http://wiki.apache.org/spamassassin/NextRelease

Users of SpamAssassin should update to this updated package, containing
version 3.0.4 which is not vulnerable to this issue and resolves these bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1266.html">CVE-2005-1266</cve>
                <bugzilla href="http://bugzilla.redhat.com/147464" id="147464">spamassassin no longer allows disabling subject rewriting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151433" id="151433">spamd generate child processes which occupies all memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159198" id="159198">CAN-2005-1266 spamassassin DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050498002" comment="spamassassin is earlier than 0:3.0.4-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050499" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:499: gedit security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:499-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-499.html" />
          <reference source="CVE" ref_id="CVE-2005-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1686.html" />
    
    <description>gEdit is a small text editor designed specifically for the GNOME GUI desktop. 

A file name format string vulnerability has been discovered in gEdit. It is
possible for an attacker to create a file with a carefully crafted name
which, when the file is opened, executes arbitrary instructions on a
victim's machine. Although it is unlikely that a user would manually open a
file with such a carefully crafted file name, a user could, for example, be
tricked into opening such a file from within an email client.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1686 to this issue. 

Users of gEdit should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1686.html">CVE-2005-1686</cve>
                <bugzilla href="http://bugzilla.redhat.com/159655" id="159655">CAN-2005-1686 filename format string vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499002" comment="gedit is earlier than 1:2.2.2-4.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499003" comment="gedit is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050499006" comment="gedit-devel is earlier than 1:2.8.1-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499007" comment="gedit-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050499005" comment="gedit is earlier than 1:2.8.1-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499003" comment="gedit is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050501" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:501: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:501-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-501.html" />
          <reference source="CVE" ref_id="CVE-2005-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2495.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides
the core functionality for the Linux graphical desktop.

Several integer overflow bugs were found in the way XFree86 parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue.

Additionally this update adds the following new features in this release:
- Support for ATI RN50/ES1000 chipsets has been added.

The following bugs were also fixed in this release:
- A problem with the X server's module loading system that led to cache
  incoherency on the Itanium architecture.

- The X server's PCI config space accesses caused contention
  with the kernel if accesses occurred while the kernel lock was held.

- X font server (xfs) crashed when accessing Type 1 fonts
  via showfont.

- A problem with the X transport library prevented X applications
  from starting if the hostname started with a digit.

- An issue where refresh rates were being restricted to 60Hz on
  some Intel i8xx systems

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-15" />
        <updated date="2005-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2495.html">CVE-2005-2495</cve>
                <bugzilla href="http://bugzilla.redhat.com/116040" id="116040">no refresh > 60 Hz for i810</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134883" id="134883">(xtrans bug) Can't open display: 50dhcp26:0.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135606" id="135606">X Font Server crashes when accessing Type 1 fonts via showfont.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153106" id="153106">ia64 elfloader cache flush</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166857" id="166857">CAN-2005-2495 multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501012" comment="XFree86-xdm is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501016" comment="XFree86-libs-data is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501046" comment="XFree86-doc is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501002" comment="XFree86 is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501014" comment="XFree86-libs is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501060" comment="XFree86-sdk is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501008" comment="XFree86-xfs is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501048" comment="XFree86-Xnest is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501058" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501018" comment="XFree86-base-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501006" comment="XFree86-font-utils is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501052" comment="XFree86-tools is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501050" comment="XFree86-Xvfb is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501010" comment="XFree86-twm is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501054" comment="XFree86-xauth is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501004" comment="XFree86-devel is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050502" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:502: sysreport security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:502-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-502.html" />
          <reference source="CVE" ref_id="CVE-2005-1760" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1760.html" />
    
    <description>Sysreport is a utility that gathers information about a system's hardware
and configuration. The information can then be used for diagnostic purposes
and debugging.

When run by the root user, sysreport includes the contents of the
/etc/sysconfig/rhn/up2date configuration file.  If up2date has been
configured to connect to a proxy server that requires an authentication
password, that password is included in plain text in the system report. 
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1760 to this issue.

Users of sysreport should update to this erratum package, which contains a
patch that removes any proxy authentication passwords.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1760.html">CVE-2005-1760</cve>
                <bugzilla href="http://bugzilla.redhat.com/159502" id="159502">CAN-2005-1760 sysreport includes proxy password in cleartext</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502002" comment="sysreport is earlier than 0:1.3.7.2-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502005" comment="sysreport is earlier than 0:1.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050504" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:504: telnet security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:504-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-504.html" />
          <reference source="CVE" ref_id="CVE-2005-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0488.html" />
    
    <description>The telnet package provides a command line telnet client. 

Gaël Delalleau discovered an information disclosure issue in the way the
telnet client handles messages from a server.  An attacker could construct
a malicious telnet server that collects information from the environment of
any victim who connects to it.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0488 to this issue.

Users of telnet should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-06-14" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0488.html">CVE-2005-0488</cve>
                <bugzilla href="http://bugzilla.redhat.com/159297" id="159297">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504002" comment="telnet is earlier than 1:0.17-26.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504004" comment="telnet-server is earlier than 1:0.17-26.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504007" comment="telnet is earlier than 1:0.17-31.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504008" comment="telnet-server is earlier than 1:0.17-31.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050505" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:505: tcpdump security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:505-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-505.html" />
          <reference source="CVE" ref_id="CVE-2005-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1267.html" />
    
    <description>Tcpdump is a command line tool for monitoring network traffic.

A denial of service bug was found in tcpdump during the processing of
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-1267 to this issue. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1267.html">CVE-2005-1267</cve>
                <bugzilla href="http://bugzilla.redhat.com/159208" id="159208">CAN-2005-1267 tcpdump BGP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505004" comment="libpcap is earlier than 14:0.8.3-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505002" comment="tcpdump is earlier than 14:3.8.2-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505006" comment="arpwatch is earlier than 14:2.1a13-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050506" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:506: mikmod security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-506.html" />
          <reference source="CVE" ref_id="CVE-2003-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0427.html" />
    
    <description>MikMod is a well known MOD music file player for UNIX-based systems.

A buffer overflow bug was found in mikmod during the processing of archive
filenames. An attacker could create a malicious archive that when opened by
mikmod could result in arbitrary code execution. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0427
to this issue. 

Users of mikmod are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0427.html">CVE-2003-0427</cve>
                <bugzilla href="http://bugzilla.redhat.com/159290" id="159290">CAN-2003-0427 mikmod flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506002" comment="mikmod is earlier than 0:3.1.6-22.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506003" comment="mikmod is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506004" comment="mikmod-devel is earlier than 0:3.1.6-22.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506005" comment="mikmod-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506007" comment="mikmod is earlier than 0:3.1.6-32.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506003" comment="mikmod is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506008" comment="mikmod-devel is earlier than 0:3.1.6-32.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506005" comment="mikmod-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050514" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:514: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 2 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:514-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-514.html" />
          <reference source="CVE" ref_id="CVE-2005-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0756.html" />
          <reference source="CVE" ref_id="CVE-2005-1265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1265.html" />
          <reference source="CVE" ref_id="CVE-2005-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1761.html" />
          <reference source="CVE" ref_id="CVE-2005-1762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1762.html" />
          <reference source="CVE" ref_id="CVE-2005-1763" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1763.html" />
          <reference source="CVE" ref_id="CVE-2005-2098" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2098.html" />
          <reference source="CVE" ref_id="CVE-2005-2099" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2099.html" />
          <reference source="CVE" ref_id="CVE-2005-2100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2100.html" />
          <reference source="CVE" ref_id="CVE-2005-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2456.html" />
          <reference source="CVE" ref_id="CVE-2005-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2490.html" />
          <reference source="CVE" ref_id="CVE-2005-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2492.html" />
          <reference source="CVE" ref_id="CVE-2005-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2555.html" />
          <reference source="CVE" ref_id="CVE-2005-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2801.html" />
          <reference source="CVE" ref_id="CVE-2005-2872" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2872.html" />
          <reference source="CVE" ref_id="CVE-2005-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3105.html" />
          <reference source="CVE" ref_id="CVE-2005-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3274.html" />
          <reference source="CVE" ref_id="CVE-2005-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3275.html" />
          <reference source="CVE" ref_id="CVE-2005-4886" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4886.html" />
          <reference source="CVE" ref_id="CVE-2006-5871" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5871.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the second regular kernel update to Red Hat Enterprise Linux 4.

New features introduced in this update include:
- Audit support
- systemtap - kprobes, relayfs
- Keyring support
- iSCSI Initiator - iscsi_sfnet 4:0.1.11-1
- Device mapper multipath support
- Intel dual core support
- esb2 chipset support
- Increased exec-shield coverage
- Dirty page tracking for HA systems
- Diskdump -- allow partial diskdumps and directing to swap

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4. 

The following security bugs were fixed in this update, detailed below with
corresponding CAN names available from the Common Vulnerabilities and
Exposures project (cve.mitre.org):

- flaws in ptrace() syscall handling on 64-bit systems that allowed a local
user to cause a denial of service (crash) (CAN-2005-0756, CAN-2005-1761,
CAN-2005-1762, CAN-2005-1763)

- flaws in IPSEC network handling that allowed a local user to cause a
denial of service or potentially gain privileges (CAN-2005-2456, CAN-2005-2555)

- a flaw in sendmsg() syscall handling on 64-bit systems that allowed a
local user to cause a denial of service or potentially gain privileges
(CAN-2005-2490)

- a flaw in sendmsg() syscall handling that allowed a local user to cause a
denial of service by altering hardware state (CAN-2005-2492)

- a flaw that prevented the topdown allocator from allocating mmap areas
all the way down to address zero (CAN-2005-1265)

- flaws dealing with keyrings that could cause a local denial of service
(CAN-2005-2098, CAN-2005-2099)

- a flaw in the 4GB split patch that could allow a local denial of service
(CAN-2005-2100)

- a xattr sharing bug in the ext2 and ext3 file systems that could cause
default ACLs to disappear (CAN-2005-2801)

- a flaw in the ipt_recent module on 64-bit architectures which could allow
a remote denial of service (CAN-2005-2872)

The following device drivers have been upgraded to new versions:

qla2100 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2200 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2300 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2322 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2xxx --------- 8.00.00b21-k to 8.01.00b5-rh2
qla6312 --------- 8.00.00b21-k to 8.01.00b5-rh2
megaraid_mbox --- 2.20.4.5 to 2.20.4.6
megaraid_mm ----- 2.20.2.5 to 2.20.2.6 
lpfc ------------ 0:8.0.16.6_x2 to 0:8.0.16.17
cciss ----------- 2.6.4 to 2.6.6
ipw2100 --------- 1.0.3 to 1.1.0
tg3 ------------- 3.22-rh to 3.27-rh
e100 ------------ 3.3.6-k2-NAPI to 3.4.8-k2-NAPI
e1000 ----------- 5.6.10.1-k2-NAPI to 6.0.54-k2-NAPI
3c59x ----------- LK1.1.19
mptbase --------- 3.01.16 to 3.02.18
ixgb ------------ 1.0.66 to 1.0.95-k2-NAPI
libata ---------- 1.10 to 1.11
sata_via -------- 1.0 to 1.1
sata_ahci ------- 1.00 to 1.01
sata_qstor ------ 0.04
sata_sil -------- 0.8 to 0.9
sata_svw -------- 1.05 to 1.06
s390: crypto ---- 1.31 to 1.57
s390: zfcp ------ 
s390: CTC-MPC ---
s390: dasd -------
s390: cio -------
s390: qeth ------

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0756.html">CVE-2005-0756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1265.html">CVE-2005-1265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1761.html">CVE-2005-1761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1762.html">CVE-2005-1762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1763.html">CVE-2005-1763</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2098.html">CVE-2005-2098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2099.html">CVE-2005-2099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2100.html">CVE-2005-2100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2456.html">CVE-2005-2456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2490.html">CVE-2005-2490</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2492.html">CVE-2005-2492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2555.html">CVE-2005-2555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2801.html">CVE-2005-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2872.html">CVE-2005-2872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3105.html">CVE-2005-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3274.html">CVE-2005-3274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3275.html">CVE-2005-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4886.html">CVE-2005-4886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5871.html">CVE-2006-5871</cve>
                <bugzilla href="http://bugzilla.redhat.com/114578" id="114578">RHEL4 U1: File Delegation, at least read-only.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130914" id="130914">RHEL4: keyring support (OpenAFS enabler)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134790" id="134790">Inspiron 8500 practically hangs when configuring b44 NIC with 1.5G memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135669" id="135669">tcsendbreak fails in compat mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137343" id="137343">RH40-beta1, embedded IDE/PCI drivers not honoring Sub ID's/Class code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140002" id="140002">[PATCH] i2o_block timeout Adaptec  2400A raid card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141783" id="141783">domain validation fails on DVD-305 when CD in drive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142989" id="142989">Terminated threads' resource usage is hidden from procps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144668" id="144668">System doesn't reboot even if kernel.panic is > 0 on RHEL-4 Beta-2.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145575" id="145575">[RHEL4-U2][Diskdump] Partial dump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145648" id="145648">Socket option IP_FREEBIND has no effect on SCTP socket.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145659" id="145659">Socket option SO_BINDTODEVICE problems with SCTP listening socket.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145976" id="145976">Sub-second mtime changes without modifying file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146187" id="146187">[RHEL4RC1] chicony usb keyboard fails, with side effects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147233" id="147233">NFSv3 over Kerberos: gss_get_mic FAILED during xdm login attempt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147496" id="147496">Sense data errors are seen when trying to access a travan tape device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149478" id="149478">Bug / data corruption on error handling in Ext3 under I/O failure condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149919" id="149919">highmem.c: fix bio error propagation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149979" id="149979">kernel panic when tar'ing data to IDE Tape device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150152" id="150152">nfsv4 callback authentication patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151222" id="151222">smp_apic_timer_interrupt() executes on kernel thread stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151315" id="151315">kernel BUG() at pageattr:107 with rmmod e1000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151323" id="151323">Kernel BUG at pageattr:107</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151429" id="151429">Fusion MPT doesn't handle multiple PCI domains correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152162" id="152162">LVM snapshots over md raid1 cause corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152440" id="152440">ppc64 arches can crash when single setpping a debugger through syscall return code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152619" id="152619">openipmi drivers missing compat_ioctl's on x86_64 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152982" id="152982">fail to mount nfs4 servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154055" id="154055">RHEL4 U1  Oracle 10G 10.0.3 aio hang running tpc-c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154100" id="154100">assertion failrue in semaphore.h caused by perfmon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154347" id="154347">spin_lock already locked by xfrm4_output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154435" id="154435">kernel dm-emc: Fix spinlock reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154442" id="154442">kernel dm-multipath: multiple pg_inits can be issued in parallel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154451" id="154451">CAN-2005-1762 x86_64 sysret exception leads to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154733" id="154733">oops when catting /proc/net/ip_conntrack_expect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155278" id="155278">Debugger killed by kernel when looking at the lowest addressed vmalloc page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155344" id="155344">add fix for IPMI/ACPI  OOPS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155354" id="155354">20050313 SCSI tape security</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155706" id="155706">CAN-2005-2801 xattr sharing bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155932" id="155932">[RHEL4-U2][Diskdump] hangs when SCSI drive is busy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156010" id="156010">[RHEL4-U2] Diskdump - swap partition support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156705" id="156705">Serial console corrupt on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157239" id="157239">Systemtap patches to be ported to RHEL4 U2 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157725" id="157725">sysctl -A returns an error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157900" id="157900">[not quite PATCH] tg3 driver crashes kernel with BCM5752 chip, newer driver is OK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158107" id="158107">Serial console turns into garbage after initialising 16550A</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158293" id="158293">nfs server intermitently claims ENOENT on existing files or directories</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158878" id="158878">CAN-2005-1265 Prevent NULL mmap in topdown model</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158883" id="158883">Annoying i2o_config kernel module messages during raidutil run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158930" id="158930">32-bit GETBLKSIZE ioctl overflows incorrectly on 64-bit hosts.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158974" id="158974">[Patch] modprobling a module signed with a key not known to the kernel can result in a panic.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159640" id="159640">proc and sysctl interface for lockd grace period do not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159671" id="159671">CAN-2005-1761 local user can use ptrace to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159739" id="159739">[Stratus RHEL4U2] csb5 functions are tagged with __init.  This causes a crash in a hot-plug environment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159765" id="159765">RHEL4 Data corruption in spite of using O_SYNC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159918" id="159918">CAN-2005-0756 x86_64 crash (ptrace-check-segment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159921" id="159921">CAN-2005-1763 x86_64 crash (x86_64-ptrace-overflow)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160028" id="160028">Kernel BUG at pageattr:107</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160518" id="160518">audit: file system and user space filtering by auid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160522" id="160522">audit: teach OOM killer about auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160524" id="160524">audit: file system attribute change tracking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160526" id="160526">audit:PATH record mode flags are wrong sometimes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160528" id="160528">audit: file system watch on block device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160547" id="160547">when removing scsi hosts commands are not leaked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160548" id="160548">when removing scsi hosts commands are not leaked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160654" id="160654">audit: kernel audits auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160663" id="160663">cable link state ignored on ethernet card (b44).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160812" id="160812">fixes exec-shield to not randomize to between end-of-binary and start-of-brk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160882" id="160882">i2o RAID monitoring memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161143" id="161143">Need export of generic_drop_inode for OCFS2 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161156" id="161156">'mt tell' fails - backported kernel bug likely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161314" id="161314">Bluetooth paring did not work anymore since update to 2.6.9-11.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161789" id="161789">GET_INDEX macro in aspm pci fixup code can overwrite end of the array</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161995" id="161995">kernel panic when rm -rf directory structure on tmpfs filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162108" id="162108">only the main thread is shown by top(1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162257" id="162257">irq stacks not being used for hardirqs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162548" id="162548">interrupt handlers run on thread's kernel stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162728" id="162728">JBD race during shutdown of a journal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163528" id="163528">/dev/tty won't open during blocking /dev/ttyS1 open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164094" id="164094">Placeholder for 2.6.x SATA update 20050724-1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164228" id="164228">Export sys_recvmesg for cluster snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164338" id="164338">fix aio hang when reading beyond EOF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164449" id="164449">RHEL4 [NETFILTER]: Fix deadlock in ip6_queue.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164450" id="164450">[NETFILTER]: Fix potential memory corruption in NAT code (aka memory NAT)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164628" id="164628">pci_scan_device can cause master abort</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164630" id="164630">panic while running fsstress to a filesystem on a mirror</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164979" id="164979">CAN-2005-2098 Error during attempt to join key management session can leave semaphore pinned</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164991" id="164991">CAN-2005-2099 Destruction of failed keyring oopses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165127" id="165127">acpi_processor_get_performance_states fails on empty table entries (_PSS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165163" id="165163">audit - syscall performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165242" id="165242">mirrors possibly reporting invalid blocks to the filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165384" id="165384">cpufreq driver hangs when using SMP Powernow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165547" id="165547">CAN-2005-2100 4G/4G split bounds checking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165560" id="165560">CAN-2005-2456 IPSEC overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165717" id="165717">ext on top of mirror attempts to access beyond end of device: dm-5: rw=0, want=16304032720, limit=20971520</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166131" id="166131">CAN-2005-2555 IPSEC lacks restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166248" id="166248">CAN-2005-2490 sendmsg compat stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166830" id="166830">CAN-2005-2492 sendmsg DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167126" id="167126">bad elf check in module-verify.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167412" id="167412">[RFC] [RHEL4 U2 patch] dual-core detection gap for i386 build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167668" id="167668">LTC17960-Kernel panic at key_put+0x4/0x19 [REGRESSION]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167703" id="167703">CAN-2005-2872 ipt_recent crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167711" id="167711">LTC18014-powernow-k8 debug messages are enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514002" comment="kernel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514006" comment="kernel-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514004" comment="kernel-doc is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514010" comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514012" comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514008" comment="kernel-smp is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050517" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:517: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:517-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-517.html" />
          <reference source="CVE" ref_id="CVE-2005-1766" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1766.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes SMIL files.
An attacker could create a specially crafted SMIL file, which when combined
with a malicious web server, could execute arbitrary code when opened by a
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1766 to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.5 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1766.html">CVE-2005-1766</cve>
                <bugzilla href="http://bugzilla.redhat.com/159871" id="159871">CAN-2005-1766 HelixPlayer heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050517002" comment="HelixPlayer is earlier than 1:1.0.5-0.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050518" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:518: gaim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:518-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-518.html" />
          <reference source="CVE" ref_id="CVE-2005-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1269.html" />
          <reference source="CVE" ref_id="CVE-2005-1934" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1934.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

Jacopo Ottaviani discovered a bug in the way Gaim handles Yahoo! Messenger
file transfers. It is possible for a malicious user to send a specially
crafted file transfer request that causes Gaim to crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1269 to this issue.

Additionally, Hugo de Bokkenrijder discovered a bug in the way Gaim parses
MSN Messenger messages. It is possible for a malicious user to send a
specially crafted MSN Messenger message that causes Gaim to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1934 to this issue.

Users of gaim are advised to upgrade to this updated package, which contains
version 1.3.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-16" />
        <updated date="2005-06-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1269.html">CVE-2005-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1934.html">CVE-2005-1934</cve>
                <bugzilla href="http://bugzilla.redhat.com/159691" id="159691">CAN-2005-1269 Gaim yahoo utf8 crasher</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159961" id="159961">CAN-2005-1934 Gaim MSN protocol DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050518002" comment="gaim is earlier than 1:1.3.1-0.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050518005" comment="gaim is earlier than 1:1.3.1-0.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050524" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:524: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:524-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-524.html" />
          <reference source="CVE" ref_id="CVE-2005-1454" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1454.html" />
          <reference source="CVE" ref_id="CVE-2005-1455" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1455.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A buffer overflow bug was found in the way FreeRADIUS escapes data in an
SQL query. An attacker may be able to crash FreeRADIUS if they cause
FreeRADIUS to escape a string containing three or less characters. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1454 to this issue.

Additionally a bug was found in the way FreeRADIUS escapes SQL data. It is
possible that an authenticated user could execute arbitrary SQL queries by
sending a specially crafted request to FreeRADIUS. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1455 to this issue.

Users of FreeRADIUS should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1454.html">CVE-2005-1454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1455.html">CVE-2005-1455</cve>
                <bugzilla href="http://bugzilla.redhat.com/156941" id="156941">CAN-2005-1454 Multiple issues in freeradius (CAN-2005-1455)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524004" comment="freeradius-mysql is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524006" comment="freeradius-postgresql is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524008" comment="freeradius-unixODBC is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524002" comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524012" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524013" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524014" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524011" comment="freeradius is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050527" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:527: openssh security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:527-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-527.html" />
          <reference source="CVE" ref_id="CVE-2005-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-1483" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1483.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. 

An error in the way OpenSSH handled GSSAPI credential delegation was
discovered. OpenSSH as distributed with Red Hat Enterprise Linux 4 contains
support for GSSAPI user authentication, typically used for supporting
Kerberos. On OpenSSH installations which have GSSAPI enabled, this flaw
could allow a user who sucessfully authenticates using a method other than
GSSAPI to be delegated with GSSAPI credentials. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2798
to this issue.

Additionally, the following bugs have been addressed:

The ssh command incorrectly failed when it was issued by the root user with
a non-default group set.

The sshd daemon could fail to properly close the client connection if
multiple X clients were forwarded over the connection and the client
session exited.

The sshd daemon could bind only on the IPv6 address family for X forwarding
if the port on IPv4 address family was already bound. The X forwarding did
not work in such cases.

This update also adds support for recording login user IDs for the auditing
service. The user ID is attached to the audit records generated from the
user's session.

All users of openssh should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2798.html">CVE-2005-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1483.html">CVE-2008-1483</cve>
                <bugzilla href="http://bugzilla.redhat.com/159331" id="159331">sshd update for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167444" id="167444">CAN-2005-2798 Improper GSSAPI credential delegation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527002" comment="openssh is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527010" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527004" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527006" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527008" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050535" version="505" class="patch">
      <metadata>
        <title>RHSA-2005:535: sudo security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:535-04" ref_url="https://rhn.redhat.com/errata/RHSA-2005-535.html" />
          <reference source="CVE" ref_id="CVE-2005-1993" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1993.html" />
    
    <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A race condition bug was found in the way sudo handles pathnames. It is
possible that a local user with limited sudo access could create
a race condition that would allow the execution of arbitrary commands as
the root user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1993 to this issue.

Users of sudo should update to this updated package, which contains a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-29" />
        <updated date="2005-06-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1993.html">CVE-2005-1993</cve>
                <bugzilla href="http://bugzilla.redhat.com/161116" id="161116">CAN-2005-1993 sudo trusted user arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535002" comment="sudo is earlier than 0:1.6.7p5-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535003" comment="sudo is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535005" comment="sudo is earlier than 0:1.6.7p5-30.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535003" comment="sudo is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050543" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:543: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:543-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-543.html" />
          <reference source="CVE" ref_id="CVE-2005-1992" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1992.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A bug was found in the way Ruby launched an XMLRPC server. If an XMLRPC
server is launched in a certain way, it becomes possible for a remote
attacker to execute arbitrary commands within the XMLRPC server. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1992 to this issue. 

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-05" />
        <updated date="2005-08-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1992.html">CVE-2005-1992</cve>
                <bugzilla href="http://bugzilla.redhat.com/161095" id="161095">CAN-2005-1992 ruby arbitrary command execution on XMLRPC server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543012" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543010" comment="irb is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543014" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543008" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543004" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543002" comment="ruby is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543006" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050550" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:550: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:550-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-550.html" />
          <reference source="CVE" ref_id="CVE-2004-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2069.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
includes the core files necessary for both the OpenSSH client and server. 

A bug was found in the way the OpenSSH server handled the MaxStartups and
LoginGraceTime configuration variables. A malicious user could connect to
the SSH daemon in such a way that it would prevent additional logins from
occuring until the malicious connections are closed. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-2069 to this issue.

Additionally, the following issues are resolved with this update:

- The -q option of the ssh client did not suppress the banner message sent
by the server, which caused errors when used in scripts.

- The sshd daemon failed to close the client connection if multiple X
clients were forwarded over the connection and the client session exited.

- The sftp client leaked memory if used for extended periods.

- The sshd daemon called the PAM functions incorrectly if the user was
unknown on the system.

All users of openssh should upgrade to these updated packages, which
contain backported patches and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2069.html">CVE-2004-2069</cve>
                <bugzilla href="http://bugzilla.redhat.com/129289" id="129289">[PATCH] SSH -q flag does not suppress banner text</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151080" id="151080">sftp over a persistent connection (days/weeks) develops a memory leak.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156996" id="156996">CAN-2004-2069 openssh DoS issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550002" comment="openssh is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050562" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:562: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:562-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-562.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0488.html" />
          <reference source="CVE" ref_id="CVE-2005-1175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1175.html" />
          <reference source="CVE" ref_id="CVE-2005-1689" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1689.html" />
    
    <description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A double-free flaw was found in the krb5_recvauth() routine which may be
triggered by a remote unauthenticated attacker.  Although no exploit is
currently known to exist, this issue could potentially be exploited to
allow arbitrary code execution on a Key Distribution Center (KDC). The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1689 to this issue. 

Daniel Wachdorf discovered a single byte heap overflow in the
krb5_unparse_name() function, part of krb5-libs. Sucessful exploitation of
this flaw would lead to a denial of service (crash). To trigger this flaw
an attacker would need to have control of a kerberos realm that shares a
cross-realm key with the target, making exploitation of this flaw unlikely.
(CAN-2005-1175). 

Gaël Delalleau discovered an information disclosure issue in the way
some telnet clients handle messages from a server. An attacker could
construct a malicious telnet server that collects information from the
environment of any victim who connects to it using the Kerberos-aware
telnet client (CAN-2005-0488).

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses the Kerberos-aware rcp to copy files from a
malicious server (CAN-2004-0175). 

All users of krb5 should update to these erratum packages which contain
backported patches to correct these issues. Red Hat would like to thank
the MIT Kerberos Development Team for their responsible disclosure of these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-07-12" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0488.html">CVE-2005-0488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1175.html">CVE-2005-1175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1689.html">CVE-2005-1689</cve>
                <bugzilla href="http://bugzilla.redhat.com/159304" id="159304">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159753" id="159753">CAN-2005-1689 double-free in krb5_recvauth</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161471" id="161471">krb5 krb5_principal_compare NULL pointer crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161611" id="161611">CAN-2004-0175 malicious rsh server can cause rcp to write to arbitrary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162255" id="162255">CAN-2005-1175 krb5 buffer overflow in KDC</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562006" comment="krb5-libs is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562004" comment="krb5-devel is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562008" comment="krb5-server is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562002" comment="krb5 is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562010" comment="krb5-workstation is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050564" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:564: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:564-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-564.html" />
          <reference source="CVE" ref_id="CVE-2005-1751" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1751.html" />
          <reference source="CVE" ref_id="CVE-2005-1921" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1921.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was discovered in the PEAR XML-RPC Server package included in PHP.
If a PHP script is used which implements an XML-RPC Server using the PEAR
XML-RPC package, then it is possible for a remote attacker to construct an
XML-RPC request which can cause PHP to execute arbitrary PHP commands as
the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1921 to this issue.

When using the default SELinux "targeted" policy on Red Hat Enterprise
Linux 4, the impact of this issue is reduced since the scripts executed by
PHP are constrained within the httpd_sys_script_t security context.

A race condition in temporary file handling was discovered in the shtool
script installed by PHP.  If a third-party PHP module which uses shtool was
compiled as root, a local user may be able to modify arbitrary files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1751 to this issue.

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-07" />
        <updated date="2005-07-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1751.html">CVE-2005-1751</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1921.html">CVE-2005-1921</cve>
                <bugzilla href="http://bugzilla.redhat.com/158904" id="158904">Incorrect descriptions for php-ncurses and php-gd packages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159000" id="159000">CAN-2005-1751 shtool insecure temporary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162044" id="162044">CAN-2005-1921 PHP PEAR XML_RPC arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564014" comment="php-odbc is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564010" comment="php-mysql is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564002" comment="php is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564012" comment="php-pgsql is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564004" comment="php-devel is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564006" comment="php-imap is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564008" comment="php-ldap is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564036" comment="php-gd is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564025" comment="php-odbc is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564023" comment="php-mysql is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564017" comment="php is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564030" comment="php-xmlrpc is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564032" comment="php-mbstring is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564024" comment="php-pgsql is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564018" comment="php-devel is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564034" comment="php-ncurses is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564026" comment="php-snmp is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564021" comment="php-imap is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564019" comment="php-pear is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564028" comment="php-domxml is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564022" comment="php-ldap is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050567" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:567: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:567-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-567.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-1174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1174.html" />
          <reference source="CVE" ref_id="CVE-2005-1175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1175.html" />
          <reference source="CVE" ref_id="CVE-2005-1689" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1689.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A double-free flaw was found in the krb5_recvauth() routine which may be
triggered by a remote unauthenticated attacker.  Red Hat Enterprise Linux 4
contains checks within glibc that detect double-free flaws.  Therefore, on
Red Hat Enterprise Linux 4 successful exploitation of this issue can only
lead to a denial of service (KDC crash).  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-1689 to this issue.

Daniel Wachdorf discovered a single byte heap overflow in the
krb5_unparse_name() function, part of krb5-libs.  Sucessful exploitation of
this flaw would lead to a denial of service (crash).  To trigger this flaw
an attacker would need to have control of a kerberos realm that shares a
cross-realm key with the target, making exploitation of this flaw unlikely.
(CAN-2005-1175).

Daniel Wachdorf also discovered that in error conditions that may occur in
response to correctly-formatted client requests, the Kerberos 5 KDC may
attempt to free uninitialized memory.  This could allow a remote attacker
to cause a denial of service (KDC crash) (CAN-2005-1174).

Gaël Delalleau discovered an information disclosure issue in the way
some telnet clients handle messages from a server. An attacker could
construct a malicious telnet server that collects information from the
environment of any victim who connects to it using the Kerberos-aware
telnet client (CAN-2005-0488).

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses the Kerberos-aware rcp to copy files from a
malicious server (CAN-2004-0175).

All users of krb5 should update to these erratum packages, which contain
backported patches to correct these issues.  Red Hat would like to thank
the MIT Kerberos Development Team for their responsible disclosure of these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-07-12" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1174.html">CVE-2005-1174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1175.html">CVE-2005-1175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1689.html">CVE-2005-1689</cve>
                <bugzilla href="http://bugzilla.redhat.com/157103" id="157103">CAN-2005-1174 krb5 buffer overflow, heap corruption in KDC (CAN-2005-1175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159304" id="159304">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159756" id="159756">CAN-2005-1689 double-free in krb5_recvauth</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161471" id="161471">krb5 krb5_principal_compare NULL pointer crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161611" id="161611">CAN-2004-0175 malicious rsh server can cause rcp to write to arbitrary files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567006" comment="krb5-libs is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567004" comment="krb5-devel is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567008" comment="krb5-server is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567002" comment="krb5 is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567010" comment="krb5-workstation is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050569" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:569: zlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-569.html" />
          <reference source="CVE" ref_id="CVE-2005-2096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2096.html" />
    
    <description>Zlib is a general-purpose lossless data compression library which is used
by many different programs.

Tavis Ormandy discovered a buffer overflow affecting Zlib version 1.2 and
above.  An attacker could create a carefully crafted compressed stream that
would cause an application to crash if the stream is opened by a user.  As
an example, an attacker could create a malicious PNG image file which would
cause a web browser or mail viewer to crash if the image is viewed.  The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2096 to this issue.

Please note that the versions of Zlib as shipped with Red Hat Enterprise
Linux 2.1 and 3 are not vulnerable to this issue.

All users should update to these erratum packages which contain a patch
from Mark Adler which corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-06" />
        <updated date="2005-07-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2096.html">CVE-2005-2096</cve>
                <bugzilla href="http://bugzilla.redhat.com/162391" id="162391">CAN-2005-2096 zlib buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050569002" comment="zlib is earlier than 0:1.2.1.2-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569003" comment="zlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050569004" comment="zlib-devel is earlier than 0:1.2.1.2-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569005" comment="zlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050571" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:571: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:571-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-571.html" />
          <reference source="CVE" ref_id="CVE-2004-2154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2154.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer for
UNIX(R) operating systems.

When processing a request, the CUPS scheduler would use case-sensitive
matching on the queue name to decide which authorization policy should be
used.  However, queue names are not case-sensitive.  An unauthorized user
could print to a password-protected queue without needing a password.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-2154 to this issue.

Please note that the version of CUPS included in Red Hat Enterprise Linux 4
is not vulnerable to this issue.

All users of CUPS should upgrade to these erratum packages which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-14" />
        <updated date="2005-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2154.html">CVE-2004-2154</cve>
                <bugzilla href="http://bugzilla.redhat.com/162405" id="162405">CAN-2004-2154 &lt;Location ...> directive is case-sensitive in cupsd.conf but should not</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571004" comment="cups-devel is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571006" comment="cups-libs is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571002" comment="cups is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050582" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:582: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:582-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-582.html" />
          <reference source="CVE" ref_id="CVE-2005-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1268.html" />
          <reference source="CVE" ref_id="CVE-2005-2088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2088.html" />
    
    <description>The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

Watchfire reported a flaw that occured when using the Apache server as an
HTTP proxy.  A remote attacker could send an HTTP request with both a
"Transfer-Encoding: chunked" header and a "Content-Length" header.  This
caused Apache to incorrectly handle and forward the body of the request in
a way that the receiving server processes it as a separate HTTP request.
This could allow the bypass of Web application firewall protection or lead
to cross-site scripting (XSS) attacks.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) assigned the name CAN-2005-2088 to this
issue.

Marc Stern reported an off-by-one overflow in the mod_ssl CRL verification
callback.  In order to exploit this issue the Apache server would need to
be configured to use a malicious certificate revocation list (CRL).   The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2005-1268 to this issue.

Users of Apache httpd should update to these errata packages that contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-25" />
        <updated date="2005-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1268.html">CVE-2005-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2088.html">CVE-2005-2088</cve>
                <bugzilla href="http://bugzilla.redhat.com/161893" id="161893">Bug 145666 is missing a ',' after REDIRECT_REMOTE_USER</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162244" id="162244">CAN-2005-2088 httpd proxy request smuggling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163013" id="163013">CAN-2005-1268 mod_ssl off-by-one</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582004" comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582006" comment="mod_ssl is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582002" comment="httpd is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582011" comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582012" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582014" comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582015" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582010" comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582013" comment="mod_ssl is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582009" comment="httpd is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050584" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:584: zlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:584-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-584.html" />
          <reference source="CVE" ref_id="CVE-2005-1849" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1849.html" />
    
    <description>Zlib is a general-purpose lossless data compression library that is used
by many different programs.

A previous zlib update, RHSA-2005:569 (CAN-2005-2096) fixed a flaw in zlib
that could allow a carefully crafted compressed stream to crash an
application. While the original patch corrected the reported overflow,
Markus Oberhumer discovered additional ways a stream could trigger an
overflow.  An attacker could create a carefully crafted compressed stream
that would cause an application to crash if the stream is opened by a user.
 As an example, an attacker could create a malicious PNG image file that
would cause a Web browser or mail viewer to crash if the image is viewed.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CAN-2005-1849 to this issue.

Note that the versions of zlib shipped with Red Hat Enterprise
Linux 2.1 and 3 are not vulnerable to this issue.

All users should update to these errata packages that contain a patch
from Mark Adler that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1849.html">CVE-2005-1849</cve>
                <bugzilla href="http://bugzilla.redhat.com/163037" id="163037">CAN-2005-1849 zlib buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050584002" comment="zlib is earlier than 0:1.2.1.2-1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569003" comment="zlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050584004" comment="zlib-devel is earlier than 0:1.2.1.2-1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569005" comment="zlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050586" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:586: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-586.html" />
          <reference source="CVE" ref_id="CVE-2005-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1937.html" />
          <reference source="CVE" ref_id="CVE-2005-2114" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2114.html" />
          <reference source="CVE" ref_id="CVE-2005-2260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2260.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2262" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2262.html" />
          <reference source="CVE" ref_id="CVE-2005-2263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2263.html" />
          <reference source="CVE" ref_id="CVE-2005-2264" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2264.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2267.html" />
          <reference source="CVE" ref_id="CVE-2005-2268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2268.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox handled synthetic events. It is possible
that Web content could generate events such as keystrokes or mouse clicks
that could be used to steal data or execute malicious JavaScript code. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-2260 to this issue.


A bug was found in the way Firefox executed Javascript in XBL controls. It
is possible for a malicious webpage to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261)

A bug was found in the way Firefox set an image as the desktop wallpaper.
If a user chooses the "Set As Wallpaper..." context menu item on a
specially crafted image, it is possible for an attacker to execute
arbitrary code on a victim's machine. (CAN-2005-2262)

A bug was found in the way Firefox installed its extensions. If a user can
be tricked into visiting a malicious webpage, it may be possible to obtain
sensitive information such as cookies or passwords. (CAN-2005-2263)

A bug was found in the way Firefox handled the _search target. It is
possible for a malicious website to inject JavaScript into an already open
webpage. (CAN-2005-2264)

A bug was found in the way Firefox handled certain Javascript functions. It
is possible for a malicious web page to crash the browser by executing
malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Firefox handled multiple frame domains. It is
possible for a frame as part of a malicious web site to inject content into
a frame that belongs to another domain. This issue was previously fixed as
CAN-2004-0718 but was accidentally disabled. (CAN-2005-1937)

A bug was found in the way Firefox handled child frames. It is possible for
a malicious framed page to steal sensitive information from its parent
page. (CAN-2005-2266)

A bug was found in the way Firefox opened URLs from media players. If a
media player opens a URL that is JavaScript, JavaScript is executed
with access to the currently open webpage. (CAN-2005-2267)

A design flaw was found in the way Firefox displayed alerts and prompts.
Alerts and prompts were given the generic title [JavaScript Application]
which prevented a user from knowing which site created them. (CAN-2005-2268)

A bug was found in the way Firefox handled DOM node names. It is possible
for a malicious site to overwrite a DOM node name, allowing certain
privileged chrome actions to execute the malicious JavaScript. (CAN-2005-2269)

A bug was found in the way Firefox cloned base objects. It is possible for
Web content to navigate up the prototype chain to gain access to privileged
chrome objects. (CAN-2005-2270)

Users of Firefox are advised to upgrade to this updated package that
contains Firefox version 1.0.6 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1937.html">CVE-2005-1937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2114.html">CVE-2005-2114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2260.html">CVE-2005-2260</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2262.html">CVE-2005-2262</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2263.html">CVE-2005-2263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2264.html">CVE-2005-2264</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2267.html">CVE-2005-2267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2268.html">CVE-2005-2268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163069" id="163069">CAN-2005-1937 multiple firefox security issues (CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050586002" comment="firefox is earlier than 0:1.0.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050587" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:587: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:587-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-587.html" />
          <reference source="CVE" ref_id="CVE-2005-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1937.html" />
          <reference source="CVE" ref_id="CVE-2005-2114" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2114.html" />
          <reference source="CVE" ref_id="CVE-2005-2260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2260.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2263.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2267.html" />
          <reference source="CVE" ref_id="CVE-2005-2268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2268.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla handled synthetic events. It is possible
that Web content could generate events such as keystrokes or mouse clicks
that could be used to steal data or execute malicious Javascript code. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-2260 to this issue. 

A bug was found in the way Mozilla executed Javascript in XBL controls. It
is possible for a malicious webpage to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261) 

A bug was found in the way Mozilla installed its extensions. If a user can
be tricked into visiting a malicious webpage, it may be possible to obtain
sensitive information such as cookies or passwords. (CAN-2005-2263)

A bug was found in the way Mozilla handled certain Javascript functions. It
is possible for a malicious webpage to crash the browser by executing
malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Mozilla handled multiple frame domains. It is
possible for a frame as part of a malicious website to inject content into
a frame that belongs to another domain. This issue was previously fixed as
CAN-2004-0718 but was accidentally disabled. (CAN-2005-1937) 

A bug was found in the way Mozilla handled child frames. It is possible for
a malicious framed page to steal sensitive information from its parent
page. (CAN-2005-2266)

A bug was found in the way Mozilla opened URLs from media players. If a
media player opens a URL which is Javascript, the Javascript executes
with access to the currently open webpage. (CAN-2005-2267)

A design flaw was found in the way Mozilla displayed alerts and prompts.
Alerts and prompts were given the generic title [JavaScript Application]
which prevented a user from knowing which site created them. (CAN-2005-2268)

A bug was found in the way Mozilla handled DOM node names. It is possible
for a malicious site to overwrite a DOM node name, allowing certain
privileged chrome actions to execute the malicious Javascript. (CAN-2005-2269)

A bug was found in the way Mozilla cloned base objects. It is possible for
Web content to traverse the prototype chain to gain access to privileged
chrome objects. (CAN-2005-2270)

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.7.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-22" />
        <updated date="2005-07-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1937.html">CVE-2005-1937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2114.html">CVE-2005-2114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2260.html">CVE-2005-2260</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2263.html">CVE-2005-2263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2267.html">CVE-2005-2267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2268.html">CVE-2005-2268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163065" id="163065">CAN-2005-1937 multiple mozilla issues (CAN-2005-2260 CAN-2005-2261 CAN-2005-2263 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587018" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587014" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587016" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587010" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587002" comment="mozilla is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587020" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587006" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587004" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587012" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587008" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587031" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587029" comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587030" comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587027" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587023" comment="mozilla is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587032" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587025" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587024" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587028" comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587026" comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587033" comment="devhelp is earlier than 0:0.9.2-2.4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050595" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:595: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:595-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-595.html" />
          <reference source="CVE" ref_id="CVE-2005-2095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2095.html" />
          <reference source="CVE" ref_id="CVE-2005-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1769.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

A bug was found in the way SquirrelMail handled the $_POST variable. If a
user is tricked into visiting a malicious URL, the user's SquirrelMail
preferences could be read or modified. The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2095 to this issue.

Several cross-site scripting bugs were discovered in SquirrelMail. An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL, or by sending them a carefully constructed HTML email message. The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1769 to this issue. 

All users of SquirrelMail should upgrade to this updated package, which
contains backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-03" />
        <updated date="2005-08-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2095.html">CVE-2005-2095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1769.html">CVE-2005-1769</cve>
                <bugzilla href="http://bugzilla.redhat.com/160241" id="160241">CAN-2005-1769 Multiple XSS issues in squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162275" id="162275">CAN-2005-2095 squirrelmail cross site posting issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050595002" comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050595005" comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050598" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:598: sysreport security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:598-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-598.html" />
          <reference source="CVE" ref_id="CVE-2005-2104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2104.html" />
    
    <description>Sysreport is a utility that gathers information about a system's hardware
and configuration. The information can then be used for diagnostic purposes
and debugging.

Bill Stearns discovered a bug in the way sysreport creates temporary files.
It is possible that a local attacker could obtain sensitive information
about the system when sysreport is run. The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2104 to this issue.

Users of sysreport should update to this erratum package, which contains a
patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2104.html">CVE-2005-2104</cve>
                <bugzilla href="http://bugzilla.redhat.com/162978" id="162978">CAN-2005-2104 sysreport insecure temporary directory usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050598002" comment="sysreport is earlier than 0:1.3.7.2-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050598005" comment="sysreport is earlier than 0:1.3.15-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050601" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:601: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:601-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-601.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled anonymous functions during
regular expression string replacement. It is possible for a malicious HTML
mail to capture a random block of client memory. The Common
Vulnerabilities and Exposures project has assigned this bug the name
CAN-2005-0989.

A bug was found in the way Thunderbird validated several XPInstall related
JavaScript objects. A malicious HTML mail could pass other objects to the
XPInstall objects, resulting in the JavaScript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Thunderbird privileged UI code handled DOM
nodes from the content window. An HTML message could install malicious
JavaScript code or steal data when a user performs commonplace actions such
as clicking a link or opening the context menu. (CAN-2005-1160)

A bug was found in the way Thunderbird executed JavaScript code. JavaScript
executed from HTML mail should run with a restricted access level,
preventing dangerous actions. It is possible that a malicious HTML mail
could execute JavaScript code with elevated privileges, allowing access to
protected data and functions. (CAN-2005-1532)

A bug was found in the way Thunderbird executed Javascript in XBL controls.
It is possible for a malicious HTML mail to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261)

A bug was found in the way Thunderbird handled certain Javascript
functions. It is possible for a malicious HTML mail to crash the client by
executing malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Thunderbird handled child frames. It is possible
for a malicious framed HTML mail to steal sensitive information from its
parent frame. (CAN-2005-2266) 

A bug was found in the way Thunderbird handled DOM node names. It is
possible for a malicious HTML mail to overwrite a DOM node name, allowing
certain privileged chrome actions to execute the malicious JavaScript.
(CAN-2005-2269)

A bug was found in the way Thunderbird cloned base objects. It is possible
for HTML content to navigate up the prototype chain to gain access to
privileged chrome objects. (CAN-2005-2270) 

Users of Thunderbird are advised to upgrade to this updated package that
contains Thunderbird version 1.0.6 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163285" id="163285">CAN-2005-0989 multiple thunderbird issues (CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050601002" comment="thunderbird is earlier than 0:1.0.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050608" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:608: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:608-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-608.html" />
          <reference source="CVE" ref_id="CVE-2005-2700" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2700.html" />
          <reference source="CVE" ref_id="CVE-2005-2728" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2728.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was discovered in mod_ssl's handling of the "SSLVerifyClient"
directive.  This flaw occurs if a virtual host is configured
using "SSLVerifyClient optional" and a directive "SSLVerifyClient
required" is set for a specific location.  For servers configured in this
fashion, an attacker may be able to access resources that should otherwise
be protected, by not supplying a client certificate when connecting.  The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2700 to this issue.

A flaw was discovered in Apache httpd where the byterange filter would
buffer certain responses into memory.  If a server has a dynamic
resource such as a CGI script or PHP script that generates a large amount
of data, an attacker could send carefully crafted requests in order to
consume resources, potentially leading to a Denial of Service.  (CAN-2005-2728)

Users of Apache httpd should update to these errata packages that contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-06" />
        <updated date="2005-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2700.html">CVE-2005-2700</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2728.html">CVE-2005-2728</cve>
                <bugzilla href="http://bugzilla.redhat.com/167102" id="167102">CAN-2005-2728 byterange memory DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167194" id="167194">CAN-2005-2700 SSLVerifyClient flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608004" comment="httpd-devel is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608006" comment="mod_ssl is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608002" comment="httpd is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608011" comment="httpd-manual is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582012" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608014" comment="httpd-suexec is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582015" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608010" comment="httpd-devel is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608013" comment="mod_ssl is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608009" comment="httpd is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050612" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:612: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:612-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-612.html" />
          <reference source="CVE" ref_id="CVE-2005-1920" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1920.html" />
    
    <description>kdelibs contains libraries for the K Desktop Environment.

A flaw was discovered affecting Kate, the KDE advanced text editor, and
Kwrite.  Depending on system settings, it may be possible for a local user
to read the backup files created by Kate or Kwrite.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1920 to
this issue.

Please note this issue does not affect Red Hat Enterprise Linux 3 or 2.1.

Users of Kate or Kwrite should update to these errata packages which
contains a backported patch from the KDE security team correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-27" />
        <updated date="2005-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1920.html">CVE-2005-1920</cve>
                <bugzilla href="http://bugzilla.redhat.com/163130" id="163130">CAN-2005-1920 Kate backup file permissions leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050612002" comment="kdelibs is earlier than 6:3.3.1-3.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050612004" comment="kdelibs-devel is earlier than 6:3.3.1-3.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050627" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:627: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:627-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-627.html" />
          <reference source="CVE" ref_id="CVE-2005-2102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2102.html" />
          <reference source="CVE" ref_id="CVE-2005-2103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2103.html" />
          <reference source="CVE" ref_id="CVE-2005-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2370.html" />
    
    <description>Gaim is an Internet Messaging client.

A heap based buffer overflow issue was discovered in the way Gaim processes
away messages. A remote attacker could send a specially crafted away
message to a Gaim user logged into AIM or ICQ that could result in
arbitrary code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2103 to this issue.

Daniel Atallah discovered a denial of service issue in Gaim. A remote
attacker could attempt to upload a file with a specially crafted name to a
user logged into AIM or ICQ, causing Gaim to crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2102 to this issue.

A denial of service bug was found in Gaim's Gadu Gadu protocol handler. A
remote attacker could send a specially crafted message to a Gaim user
logged into Gadu Gadu, causing Gaim to crash.  Please note that this issue
only affects PPC and IBM S/390 systems running Gaim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2370 to this issue.

Users of gaim are advised to upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2102.html">CVE-2005-2102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2103.html">CVE-2005-2103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2370.html">CVE-2005-2370</cve>
                <bugzilla href="http://bugzilla.redhat.com/165392" id="165392">CAN-2005-2370 gadu gadu memory alignment issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165400" id="165400">CAN-2005-2102 gaim AIM invalid filename DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165402" id="165402">CAN-2005-2103 Gaim malformed away message remote code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050627002" comment="gaim is earlier than 1:1.3.1-0.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050627005" comment="gaim is earlier than 1:1.3.1-0.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050639" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:639: kdenetwork security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:639-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-639.html" />
          <reference source="CVE" ref_id="CVE-2005-1852" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1852.html" />
          <reference source="CVE" ref_id="CVE-2005-2369" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2369.html" />
          <reference source="CVE" ref_id="CVE-2005-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2370.html" />
          <reference source="CVE" ref_id="CVE-2005-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2448.html" />
    
    <description>The kdenetwork package contains networking applications for the K Desktop
Environment.  Kopete is a KDE instant messenger which supports a number of
protocols including ICQ, MSN, Yahoo, Jabber, and Gadu-Gadu.

Multiple integer overflow flaws were found in the way Kopete processes
Gadu-Gadu messages. A remote attacker could send a specially crafted
Gadu-Gadu message which would cause Kopete to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-1852 to this issue.

In order to be affected by this issue, a user would need to have registered
with Gadu-Gadu and be signed in to the Gadu-Gadu server in order to receive
a malicious message.  In addition, Red Hat believes that the Exec-shield
technology (enabled by default in Red Hat Enterprise Linux 4) would block
attempts to remotely exploit this vulnerability.

Note that this issue does not affect Red Hat Enterprise Linux 2.1 or 3.

Users of Kopete should update to these packages which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1852.html">CVE-2005-1852</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2369.html">CVE-2005-2369</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2370.html">CVE-2005-2370</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2448.html">CVE-2005-2448</cve>
                <bugzilla href="http://bugzilla.redhat.com/163811" id="163811">CAN-2005-1852 Kopete gadu-gadu flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639002" comment="kdenetwork is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639006" comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050639007" comment="kdenetwork-nowlistening is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639004" comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050640" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:640: fetchmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:640-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-640.html" />
          <reference source="CVE" ref_id="CVE-2005-2335" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2335.html" />
    
    <description>Fetchmail is a remote mail retrieval and forwarding utility.

A buffer overflow was discovered in fetchmail's POP3 client.  A malicious
server could cause send a carefully crafted message UID and cause fetchmail
to crash or potentially execute arbitrary code as the user running
fetchmail.  The Common Vulnerabilities and Exposures project assigned the
name CAN-2005-2335 to this issue.

Users of fetchmail should update to this erratum package which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-25" />
        <updated date="2005-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2335.html">CVE-2005-2335</cve>
                <bugzilla href="http://bugzilla.redhat.com/163816" id="163816">CAN-2005-2335 fetchmail overflow from malicious pop3 server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640002" comment="fetchmail is earlier than 0:6.2.0-3.el3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640005" comment="fetchmail is earlier than 0:6.2.5-6.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050659" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:659: binutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:659-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-659.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>Binutils is a collection of utilities used for the creation of executable
code. A number of bugs were found in various binutils tools.  

Several integer overflow bugs were found in binutils. If a user is tricked
into processing a specially crafted executable with utilities such as
readelf, size, strings, objdump, or nm, it may allow the execution of
arbitrary code as the user running the utility. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1704
to this issue.

Additionally, the following bugs have been fixed:

-- correct alignment of .tbss section if the requested alignment
   of .tbss is bigger than requested alignment of .tdata section
-- by default issue an error if IA-64 hint@pause instruction is
   put into the B slot, add assembler command line switch to
   override this behaviour

All users of binutils should upgrade to this updated package, which
contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/157983" id="157983">gcc produces inadequate alignment for __thread vars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164364" id="164364">CAN-2005-1704 Integer overflow in the Binary File Descriptor (BFD) library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659002" comment="binutils is earlier than 0:2.14.90.0.4-39" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659003" comment="binutils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050663" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:663: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 6 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:663-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-663.html" />
          <reference source="CVE" ref_id="CVE-2004-0181" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0181.html" />
          <reference source="CVE" ref_id="CVE-2004-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1056.html" />
          <reference source="CVE" ref_id="CVE-2005-0124" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0124.html" />
          <reference source="CVE" ref_id="CVE-2005-0136" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0136.html" />
          <reference source="CVE" ref_id="CVE-2005-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0179.html" />
          <reference source="CVE" ref_id="CVE-2005-0210" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0210.html" />
          <reference source="CVE" ref_id="CVE-2005-0400" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0400.html" />
          <reference source="CVE" ref_id="CVE-2005-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0504.html" />
          <reference source="CVE" ref_id="CVE-2005-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0756.html" />
          <reference source="CVE" ref_id="CVE-2005-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0815.html" />
          <reference source="CVE" ref_id="CVE-2005-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1761.html" />
          <reference source="CVE" ref_id="CVE-2005-1762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1762.html" />
          <reference source="CVE" ref_id="CVE-2005-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1767.html" />
          <reference source="CVE" ref_id="CVE-2005-1768" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1768.html" />
          <reference source="CVE" ref_id="CVE-2005-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2456.html" />
          <reference source="CVE" ref_id="CVE-2005-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2490.html" />
          <reference source="CVE" ref_id="CVE-2005-2553" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2553.html" />
          <reference source="CVE" ref_id="CVE-2005-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2555.html" />
          <reference source="CVE" ref_id="CVE-2005-3273" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3273.html" />
          <reference source="CVE" ref_id="CVE-2005-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3274.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the sixth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - diskdump support on HP Smart Array devices
  - netconsole/netdump support over bonded interfaces
  - new chipset and device support via PCI table updates
  - support for new "oom-kill" and "kscand_work_percent" sysctls
  - support for dual core processors and ACPI Power Management timers on
      AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement in
the reliability and scalability of Red Hat Enterprise Linux 3.

There were numerous driver updates and security fixes (elaborated below).
Other key areas affected by fixes in this update include kswapd, inode
handling, the SATA subsystem, diskdump handling, ptrace() syscall support,
and signal handling.

The following device drivers have been upgraded to new versions:

  3w-9xxx ---- 2.24.03.008RH
  cciss ------ 2.4.58.RH1
  e100 ------- 3.4.8-k2
  e1000 ------ 6.0.54-k2
  emulex ----- 7.3.2
  fusion ----- 2.06.16i.01
  iscsi ------ 3.6.2.1
  ipmi ------- 35.4
  lpfcdfc ---- 1.2.1
  qlogic ----- 7.05.00-RH1
  tg3 -------- 3.27RH

The following security bugs were fixed in this update:

  - a flaw in syscall argument checking on Itanium systems that allowed
    a local user to cause a denial of service (crash)  (CAN-2005-0136)

  - a flaw in stack expansion that allowed a local user of mlockall()
    to cause a denial of service (memory exhaustion)  (CAN-2005-0179)

  - a small memory leak in network packet defragmenting that allowed a
    remote user to cause a denial of service (memory exhaustion) on
    systems using netfilter  (CAN-2005-0210)

  - flaws in ptrace() syscall handling on AMD64 and Intel EM64T systems
    that allowed a local user to cause a denial of service (crash)
    (CAN-2005-0756, CAN-2005-1762, CAN-2005-2553)

  - flaws in ISO-9660 file system handling that allowed the mounting of
    an invalid image on a CD-ROM to cause a denial of service (crash)
    or potentially execute arbitrary code  (CAN-2005-0815)

  - a flaw in ptrace() syscall handling on Itanium systems that allowed
    a local user to cause a denial of service (crash)  (CAN-2005-1761)

  - a flaw in the alternate stack switching on AMD64 and Intel EM64T
    systems that allowed a local user to cause a denial of service
    (crash)  (CAN-2005-1767)

  - race conditions in the ia32-compat support for exec() syscalls on
    AMD64, Intel EM64T, and Itanium systems that could allow a local
    user to cause a denial of service (crash)  (CAN-2005-1768)

  - flaws in IPSEC network handling that allowed a local user to cause
    a denial of service or potentially gain privileges  (CAN-2005-2456,
    CAN-2005-2555)

  - a flaw in sendmsg() syscall handling on 64-bit systems that allowed
    a local user to cause a denial of service or potentially gain
    privileges  (CAN-2005-2490)

  - flaws in unsupported modules that allowed denial-of-service attacks
    (crashes) or local privilege escalations on systems using the drm,
    coda, or moxa modules  (CAN-2004-1056, CAN-2005-0124, CAN-2005-0504)

  - potential leaks of kernel data from jfs and ext2 file system handling
    (CAN-2004-0181, CAN-2005-0400)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0181.html">CVE-2004-0181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1056.html">CVE-2004-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0124.html">CVE-2005-0124</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0136.html">CVE-2005-0136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0179.html">CVE-2005-0179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0210.html">CVE-2005-0210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0400.html">CVE-2005-0400</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0504.html">CVE-2005-0504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0756.html">CVE-2005-0756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0815.html">CVE-2005-0815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1761.html">CVE-2005-1761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1762.html">CVE-2005-1762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1767.html">CVE-2005-1767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1768.html">CVE-2005-1768</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2456.html">CVE-2005-2456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2490.html">CVE-2005-2490</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2553.html">CVE-2005-2553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2555.html">CVE-2005-2555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3273.html">CVE-2005-3273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3274.html">CVE-2005-3274</cve>
                <bugzilla href="http://bugzilla.redhat.com/79086" id="79086">Request for enhancement for callback function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/98542" id="98542">iostat -x shows infeasible avgqu-sz results and max util</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/99502" id="99502">LTC3549 - ps wchan broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116037" id="116037">Existence of race condition in Linux SD driver that leads to a deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116317" id="116317">symbolic links have invalid permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116900" id="116900">RHEL3_U4 Data corruption in spite of using O_SYNC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119451" id="119451">System can hang while running multiple instances of fdisk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121041" id="121041">CVE-2004-0181 jfs infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122982" id="122982">microcode_ctl errors with modprobe: Can't locate module char-major-10-184</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123331" id="123331">LUN  i not getting registered</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128428" id="128428">Opteron gettimeofday granularity problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128788" id="128788">RHEL3 U6: Diskdump support for Compaq Smart Array Controllers (cciss)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128907" id="128907">iostat -x 1 5 give bogus statistics...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129853" id="129853">RHEL3 U4:  need netdump to work with the bonding driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131029" id="131029">gart errors when using 2.4.21-15.0.3.EL.smp or -9.0.1 on AMD64 quad system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131136" id="131136">[Patch] Simultaneous calls to open() on a usb device hangs the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131886" id="131886">__put_task_struct unresolved when loading externally compiled module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132754" id="132754">char-major-10-184 microcode error with kernel 2.4.21-15.ELhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134579" id="134579">bogus data in /proc/partitions for IDE whole-disk device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137788" id="137788">Extraneous data in option name for scsi_mod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138192" id="138192">gart errors when using 2.4.21-20.EL on HP DL585</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138534" id="138534">CVE-2004-1056 insufficient locking checks in DRM code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139033" id="139033">RHEL3 U5: netdump does not work over bonded interfaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139113" id="139113">System hangs for 15-45 seconds on RHEL3 / kernel 2.4.21-20.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140849" id="140849">"fdisk -l" broken when over 26 EMC Powerpath disks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142263" id="142263">Only 16 EMC powerpath LUNs usable with LVM1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142532" id="142532">error unmounting /var filesystem while shutdown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142586" id="142586">Potential kernel DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142856" id="142856">'ghosted' autofs shares disappear</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142960" id="142960">Unable to umount /var during shutdown process when connected with ssh</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143823" id="143823">[PATCH] Stale POSIX flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144524" id="144524">CVE-2005-0179 RLIMIT_MEMLOCK bypass and (2.6) unprivileged user DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144781" id="144781">Kernel panic in shutdown path when iSCSI LUNs are mounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145476" id="145476">netdump client/server problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145551" id="145551">Use of bonding driver in mode 5 can cause multicast packet loss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145950" id="145950">high loads / high iowait / up 100% cpu time for kscand on oracle box</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146080" id="146080">CVE-2005-0124 Coverity: coda fs flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146105" id="146105">CVE-2005-0504 moxa CAP_SYS_RAWIO missing (-unsupported)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146460" id="146460">Need openIPMI driver to work with IBM's x336 BMC [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147823" id="147823">FEAT: RHEL3 U6: Enable dual-core processors from Intel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148862" id="148862">CVE-2005-0136 ptrace corner cases on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149011" id="149011">Oracle 8 import of Oracle 9 database can lock system.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149405" id="149405">LTC13257-LTPstress sigaction01 Testcase Ends up Segmentation Fault [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149636" id="149636">Kernel panic (EIP is at find_inode)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149691" id="149691">No data avaliable for eth card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149965" id="149965">panic at ia64_leave_kernel  [kernel] 0x1 (2.4.21-27.EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150019" id="150019">Don't oom kill TASK_UNINTERRUPTIBLE processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150130" id="150130">e1000 has memory leak when run continuously getting new dhcp leases.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150209" id="150209">Over time, autofs leaks kernel memory in the size-256 slab</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151054" id="151054">kernel panic when bringing up and down multiple interfaces simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151488" id="151488">sk98lin driver drops udp packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151920" id="151920">8GB SMP servers appear to hang in VM subsystem under stress</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152400" id="152400">CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152406" id="152406">CVE-2005-0815 isofs range checking flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153775" id="153775">[RHEL3-U6][Diskdump] Backtrace of OS_INIT doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154245" id="154245">RHEL3 U4 - kswapd/rpciod deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154678" id="154678">[Texas Instruments] nfs bindresvport: Address already in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154797" id="154797">[RHEL3 U6] diskdump fails with block_order=8</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154925" id="154925">[RHEL3 U6] Diskdump fails if module parameter 'block_order' has too big value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155244" id="155244">Kernel Panics on kernel 2.4.21-27</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155259" id="155259">[LSI Logic] Feature RHEL: Add mpt fusion SAS support, and new PCI IDs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155289" id="155289">[RHEL 3 U6]inode_lock deadlock/race?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155365" id="155365">CVE-2005-3273 ROSE ndigis verification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155473" id="155473">ext3 data corruption under Samba share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155978" id="155978">CVE-2005-1762 x86_64 sysret exception leads to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156142" id="156142">kernel may oops if more  than 4k worth of string data returned in /proc/devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156364" id="156364">[RHEL3] IPv6 Neighbor Cache : RHEL 3.0 does not update the IsRouter flag in the cache entry and improperly remove router from the Default Router List.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156608" id="156608">[RHEL3 U4] The system clock gains much time when netconle is activated.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156644" id="156644">CRM 479318 Unexpected IO-APIC on Opteron system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156831" id="156831">sd _mod doesn't handle removable drives (USB floppy) well</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156923" id="156923">PPC64 not setting backchain in signal frames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156985" id="156985">FEAT: RHEL3 U6: cciss driver updates (STOPSHIP)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156989" id="156989">FEAT: RH EL 3 U6: diskdump driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156991" id="156991">RHEL3 U6: Add 'ht' flag in EM64T /proc/cpuinfo [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156993" id="156993">FEAT: RHEL3 U6: Add ICH4L support to kernel (MEDIUM)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156994" id="156994">529692 - /proc/stat documentation is out of date.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156998" id="156998">RHEL 3 U6: Use of Performance Monitoring Counters based on Model number (x86-64)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157075" id="157075">When an AX100i SP reboot occurs, the Cisco iSCSI driver doesnt log back into array.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157434" id="157434">FEAT RHEL3 U6:  Need e1000 driver Update to v.6.0.54 or higher (MUSTFIX)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157439" id="157439">LTC14642-NetDump is too slow to dump...[PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157446" id="157446">[RFE] [RHEL3 U6]Update 3w-9xxx driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157571" id="157571">[CRM 511714] bonding and arp ping failure detection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157669" id="157669">attempt to access beyond end of device: ext2 symlink/EA problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157846" id="157846">Potential kernel panic with stale POSIX locks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157849" id="157849">CVE-2005-3274 IPVS panic at ip_vs_conn_flush() when unloading ip_vs module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158358" id="158358">Updated Qlogic driver is requested in RHEL 3 U6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158456" id="158456">Update Emulex driver in RHEL 3 U6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158457" id="158457">Long tape commands (e.g. erase)  timeout on dpt_i2o.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158459" id="158459">RHEL 3 configures non-existent SCSI target devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158581" id="158581">FEAT RHEL3U6:  new devices supported by tg3 (STOPSHIP)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158724" id="158724">CVE-2005-0210 dst leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158814" id="158814">FEAT: [RHEL3 U6] add PCI_VENDOR_ID_NEC to megaraid subsysvid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158817" id="158817">Adding 3pardata to the scsi device whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158877" id="158877">[RHEL3 U4] setsockopt SO_RCVTIMEO call fails from a 32 bit binary running on a  x86_64 system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158880" id="158880">[Patch] RHEL3 U6: lower severity of blk: queue xxxx printks (~MF)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159045" id="159045">CVE-2005-1767 x86_64 crashes from context switches on stk-seg-fault stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159300" id="159300">FEAT:  RHEL3 U6:  Update e100 driver to later than v.3.4.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159330" id="159330">x86_64 kernel stops allocating memory too early when overcommit_memory set to strict</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159420" id="159420">RHEL3 U6: ESB2 support (PATA, SATA, USB, SMBUS, LPC, Audio and AHCI)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159790" id="159790">ptrace changes to registers during ia32 syscall tracing stop are lost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159814" id="159814">x86-64 PTRACE_SETOPTIONS does not support most option flags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159823" id="159823">CVE-2005-1761 local user can use ptrace to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159915" id="159915">CVE-2005-1762 x86_64 crash (ptrace-canonical)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159917" id="159917">CVE-2005-0756 x86_64 crash (ptrace-check-segment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159938" id="159938">Diskdump disk controllers support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159979" id="159979">Fix dangling pointer in acpi_pci_root_add()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159989" id="159989">[RHEL3][PATCH] suppress medum-not-present messages from idefloppy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159991" id="159991">[taroon patch] fix for indefinite postponement under __alloc_pages()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159992" id="159992">Add docs detailing which drivers support netconsole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159993" id="159993">CVE-2005-2553 x86_64 fix for 32-bit ptrace find_target() oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160093" id="160093">[RHEL3][PATCH] suppress medum-not-present messages from idefloppy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160199" id="160199">CVE-2005-1768 64bit execve() race leads to buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160392" id="160392">Memory Leak in autofs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160400" id="160400">The AHCI driver was incorrectly resetting the hardware on error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160495" id="160495">RHEL 3 U5 code base contains duplicate USB ESSENTIAL_REALITY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160664" id="160664">cable link state ignored on ethernet card (b44).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160752" id="160752">accounting of SETITIMER_PROF inaccurate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160799" id="160799">Kernel panic: pci_map_single: high address but no IOMMU.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160820" id="160820">nVidia driver requires upstream  page_attr patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161097" id="161097">CRM 565876: samba-3.0.8pre1-smbmnt.patch to fix smbmount UID wraparound bug for RHEL3 Samba packages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161238" id="161238">superbh function causing a server to crash when Veritas Volume Manager Modules for VxVM 4.0 are loaded.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161657" id="161657">iscsi_sfnet driver does not calculate ConnFailTimeout correctly when greater than 15 secs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161957" id="161957">CRM: 507606 / short freezes on Informix server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161986" id="161986">RHEL3 U5 panic in kmem_cache_grow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162103" id="162103">add SGI scsi devices to list in scsi_scan.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162603" id="162603">dpt_i2o driver oopses on insmod in U5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163152" id="163152">Initiator does not retry login on target error when PortalFailover is disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164074" id="164074">Placeholder for 2.4.x SATA update 20050723-1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164185" id="164185">rpm install of -33.EL on ia64 gets unresolved pm_power_off symbol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164226" id="164226">User-mode program run on IA64 AS 3.0 causes system to crash due to invalid stack pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164819" id="164819">[RHEL3U6] diskdump - scsi dump fails with module CRC error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165467" id="165467">[RHEL3 U6] Fix to update openipmi drivers for Dell 8G server line (MUSTFIX)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165565" id="165565">CVE-2005-2456 IPSEC overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165739" id="165739">LTC14996-IPMI driver is broken on multiple platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165841" id="165841">[RHEL3U6] diskdump fails with machine check error on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165850" id="165850">Disable FAN processing in Emulex lpfc driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165866" id="165866">Add Invista to RHEL 3 SCSI Whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165993" id="165993">NFS deadlock when multiple processes creating/deleting a file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166066" id="166066">IBM TapeLibrary 3583</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166132" id="166132">CVE-2005-2555 IPSEC lacks restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166172" id="166172">Kernel crash on 2.4.21-34 base due to kiobuf_init() setting the initialized state when expand_kiobuf() was not called.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166329" id="166329">CVE-2005-2490 sendmsg compat stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167047" id="167047">cciss, add pci id for P400</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167222" id="167222">[BETA RHEL3 U6] kernel panic while booting numa=off on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167265" id="167265">drivers/addon/lpfc/lpfcdfc/Makefile change causing intermittent build failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167369" id="167369">[RHEL3] cosmetic change to IPMI drivers to update version revision number</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663004" comment="kernel-source is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663002" comment="kernel is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663006" comment="kernel-doc is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663016" comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663018" comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663008" comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663014" comment="kernel-smp is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050670" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:670: xpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:670-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-670.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

A flaw was discovered in Xpdf in that an attacker could construct a
carefully crafted PDF file that would cause Xpdf to consume all available
disk space in /tmp when opened. The Common Vulnerabilities and Exposures
project assigned the name CAN-2005-2097 to this issue.

Note this issue does not affect the version of Xpdf in Red Hat Enterprise
Linux 3 or 2.1.

Users of xpdf should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163918" id="163918">CAN-2005-2097 xpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050670002" comment="xpdf is earlier than 1:3.00-11.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050671" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:671: kdegraphics security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:671-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-671.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A flaw was discovered in kpdf.  An attacker could construct a carefully
crafted PDF file that would cause kpdf to consume all available disk space
in /tmp when opened. The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-2097 to this issue.

Note this issue does not affect Red Hat Enterprise Linux 3 or 2.1.

Users of kpdf should upgrade to these updated packages, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163925" id="163925">CAN-2005-2097 kpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050671002" comment="kdegraphics is earlier than 7:3.3.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050671004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050673" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:673: binutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:673-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-673.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>Binutils is a collection of utilities used for the creation of executable
code. A number of bugs were found in various binutils tools.  

If a user is tricked into processing a specially crafted executable with
utilities such as readelf, size, strings, objdump, or nm, it may allow the
execution of arbitrary code as the user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1704 to
this issue.

In addition, the following bugs have been fixed:

-- by default issue an error if IA-64 hint@pause instruction is
   put into the B slot, add assembler command line switch to
   override this behaviour
-- fix linker's --emit-relocs with .gnu.warning.* section symbols
-- fix gprof on 64-bit ppc binaries and libraries
-- fix gas mapping of register names to dwarf2 register numbers
   in CFI directives

All users of binutils should upgrade to this updated package, which
contains patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/159894" id="159894">CAN-2005-1704 Integer overflow in the Binary File Descriptor (BFD) library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162545" id="162545">wrong dwarf register numbers generated</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050673002" comment="binutils is earlier than 0:2.15.92.0.2-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659003" comment="binutils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050674" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:674: perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:674-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-674.html" />
          <reference source="CVE" ref_id="CVE-2005-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0448.html" />
    
    <description>Perl is a high-level programming language commonly used for system     
administration utilities and Web programming.    

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module
removed directory trees. If a local user has write permissions to a
subdirectory within the tree being removed by File::Path::rmtree, it is
possible for them to create setuid binary files. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0448
to this issue.    

This update also addresses the following issues:

-- Perl interpreter caused a segmentation fault when environment    
changes occurred during runtime.

-- Code in lib/FindBin contained a regression that caused problems with  
 MRTG software package.

-- Perl incorrectly declared it provides an FCGI interface where it in fact
  did not.    

Users of Perl are advised to upgrade to these updated packages, which 
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0448.html">CVE-2005-0448</cve>
                <bugzilla href="http://bugzilla.redhat.com/127023" id="127023">perl fails "lib/FindBin" test (breaks MRTG)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148848" id="148848">Packing fault with perl and FCGI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155888" id="155888">perl-suidperl package has an extra .1 release suffix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157694" id="157694">CAN-2005-0448 perl File::Path.pm rmtree race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050674004" comment="perl-suidperl is earlier than 3:5.8.5-16.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050674002" comment="perl is earlier than 3:5.8.5-16.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050685" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:685: mysql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:685-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-685.html" />
          <reference source="CVE" ref_id="CVE-2005-1636" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1636.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries.

An insecure temporary file handling bug was found in the mysql_install_db
script. It is possible for a local user to create specially crafted files
in /tmp which could allow them to execute arbitrary SQL commands during
database installation. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1636 to this issue.

These packages update mysql to version 4.1.12, fixing a number of problems.
Also, support for SSL-encrypted connections to the database server is now
provided.

All users of mysql are advised to upgrade to these updated packages.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1636.html">CVE-2005-1636</cve>
                <bugzilla href="http://bugzilla.redhat.com/158688" id="158688">CAN-2005-1636 mysql insecure temporary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163694" id="163694">Parser issue with subqueries involving unions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685002" comment="mysql is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685004" comment="mysql-server is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685008" comment="mysql-bench is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685006" comment="mysql-devel is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050687" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:687: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:687-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-687.html" />
          <reference source="CVE" ref_id="CVE-2005-2360" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2360.html" />
          <reference source="CVE" ref_id="CVE-2005-2361" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2361.html" />
          <reference source="CVE" ref_id="CVE-2005-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2362.html" />
          <reference source="CVE" ref_id="CVE-2005-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2363.html" />
          <reference source="CVE" ref_id="CVE-2005-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2364.html" />
          <reference source="CVE" ref_id="CVE-2005-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2365.html" />
          <reference source="CVE" ref_id="CVE-2005-2366" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2366.html" />
          <reference source="CVE" ref_id="CVE-2005-2367" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2367.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-2360, CAN-2005-2361,
CAN-2005-2362, CAN-2005-2363, CAN-2005-2364, CAN-2005-2365, CAN-2005-2366,
and CAN-2005-2367 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.12 which is not vulnerable to these issues.

Note: To reduce the risk of future vulnerabilities in Ethereal, the
ethereal and tethereal programs in this update have been compiled as
Position Independant Executables (PIE) for Red Hat Enterprise Linux 3 and
4.  In addition FORTIFY_SOURCE has been enabled for Red Hat Enterprise
Linux 4 packages to provide compile time and runtime buffer checks.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-10" />
        <updated date="2005-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2360.html">CVE-2005-2360</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2361.html">CVE-2005-2361</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2362.html">CVE-2005-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2363.html">CVE-2005-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2364.html">CVE-2005-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2365.html">CVE-2005-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2366.html">CVE-2005-2366</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2367.html">CVE-2005-2367</cve>
                <bugzilla href="http://bugzilla.redhat.com/164243" id="164243">CAN-2005-2360 Multiple ethereal flaws (CAN-2005-2361 CAN-2005-2362 CAN-2005-2363 CAN-2005-2364 CAN-2005-2365 CAN-2005-2366 CAN-2005-2367)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687004" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687002" comment="ethereal is earlier than 0:0.10.12-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687008" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687007" comment="ethereal is earlier than 0:0.10.12-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050706" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:706: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:706-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-706.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer for
UNIX(R) operating systems.

When processing a PDF file, bounds checking was not correctly performed on
some fields.  This could cause the pdftops filter (running as user "lp") to
crash.  The Common Vulnerabilities and Exposures project has assigned the
name CAN-2005-2097 to this issue.

All users of CUPS should upgrade to these erratum packages, which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/164510" id="164510">CAN-2005-2097 pdf flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706004" comment="cups-devel is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706006" comment="cups-libs is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706002" comment="cups is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706009" comment="cups is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050708" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:708: gpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:708-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-708.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The gpdf package is an GNOME based viewer for Portable Document Format
(PDF) files.

Marcus Meissner reported a flaw in gpdf.  An attacker could construct a
carefully crafted PDF file that would cause gpdf to consume all available
disk space in /tmp when opened. The Common Vulnerabilities and Exposures
project assigned the name CAN-2005-2097 to this issue.

Note that this issue does not affect the version of gpdf in Red Hat
Enterprise Linux 3 or 2.1.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-10" />
        <updated date="2005-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163920" id="163920">CAN-2005-2097 gpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050708002" comment="gpdf is earlier than 0:2.8.2-4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050709" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:709: gdb security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:709-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-709.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
          <reference source="CVE" ref_id="CVE-2005-1705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1705.html" />
    
    <description>GDB, the GNU debugger, allows debugging of programs written in C, C++,
and other languages by executing them in a controlled fashion, then
printing their data.

Several integer overflow bugs were found in gdb. If a user is tricked
into processing a specially crafted executable file, it may allow the
execution of arbitrary code as the user running gdb. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1704 to this issue.

A bug was found in the way gdb loads .gdbinit files. When a user executes
gdb, the local directory is searched for a .gdbinit file which is then
loaded. It is possible for a local user to execute arbitrary commands as
the victim running gdb by placing a malicious .gdbinit file in a location
where gdb may be run. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1705 to this issue.

This updated package also addresses the following issues:

- GDB on ia64 had previously implemented a bug fix to work-around a kernel
problem when creating a core file via gcore.  The bug fix caused a
significant slow-down of gcore.

- GDB on ia64 issued an extraneous warning when gcore was used.

- GDB on ia64 could not backtrace over a sigaltstack.

- GDB on ia64 could not successfully do an info frame for a signal trampoline.

- GDB on AMD64 and Intel EM64T had problems attaching to a 32-bit process.

- GDB on AMD64 and Intel EM64T was not properly handling threaded watchpoints.

- GDB could not build with gcc4 when -Werror flag was set.

- GDB had problems printing inherited members of C++ classes.

- A few updates from mainline sources concerning Dwarf2 partial die in
cache support, follow-fork support, interrupted syscall support, and
DW_OP_piece read support.

All users of gdb should upgrade to this updated package, which resolves
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1705.html">CVE-2005-1705</cve>
                <bugzilla href="http://bugzilla.redhat.com/158680" id="158680">CAN-2005-1704 Integer overflow in gdb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158684" id="158684">CAN-2005-1705 gdb arbitrary command execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160339" id="160339">GDB fails to correctly report frame information</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050709002" comment="gdb is earlier than 0:6.3.0.0-1.63" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050709003" comment="gdb is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050743" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:743: netpbm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:743-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-743.html" />
          <reference source="CVE" ref_id="CVE-2005-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2471.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts PostScript files into PBM, PGM
or PPM files.  An attacker could create a carefully crafted PostScript file
in such a way that it could execute arbitrary commands when the
file is processed by a victim using pstopnm.  The Common Vulnerabilities
and Exposures project assigned the name CAN-2005-2471 to this issue.

All users of netpbm should upgrade to the updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-22" />
        <updated date="2005-08-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2471.html">CVE-2005-2471</cve>
                <bugzilla href="http://bugzilla.redhat.com/165354" id="165354">CAN-2005-2471 netpbm should use the -dSAFER option when calling Ghostscript</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743002" comment="netpbm is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743004" comment="netpbm-devel is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743006" comment="netpbm-progs is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743009" comment="netpbm is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743010" comment="netpbm-devel is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743011" comment="netpbm-progs is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050745" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:745: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:745-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-745.html" />
          <reference source="CVE" ref_id="CVE-2005-2368" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2368.html" />
    
    <description>VIM (VIsual editor iMproved) is a version of the vi editor.   

A bug was found in the way VIM processes modelines. If a user with
modelines enabled opens a text file with a carefully crafted modeline,
arbitrary commands may be executed as the user running VIM. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2368
to this issue.
 
Users of VIM are advised to upgrade to these updated packages, which
resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-22" />
        <updated date="2005-08-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2368.html">CVE-2005-2368</cve>
                <bugzilla href="http://bugzilla.redhat.com/164279" id="164279">CAN-2005-2368 vim modeline arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745002" comment="vim is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745004" comment="vim-common is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745015" comment="vim-minimal is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745013" comment="vim is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745017" comment="vim-X11 is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745014" comment="vim-common is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745016" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050748" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:748: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:748-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-748.html" />
          <reference source="CVE" ref_id="CVE-2005-2498" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2498.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was discovered in the PEAR XML-RPC Server package included in PHP. If
a PHP script is used which implements an XML-RPC Server using the PEAR
XML-RPC package, then it is possible for a remote attacker to construct an
XML-RPC request which can cause PHP to execute arbitrary PHP commands as
the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2498 to this issue.

When using the default SELinux "targeted" policy on Red Hat Enterprise
Linux 4, the impact of this issue is reduced since the scripts executed by
PHP are constrained within the httpd_sys_script_t security context.

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-19" />
        <updated date="2005-08-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2498.html">CVE-2005-2498</cve>
                <bugzilla href="http://bugzilla.redhat.com/165846" id="165846">CAN-2005-2498 PHP PEAR:XMLRPC eval code injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748014" comment="php-odbc is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748010" comment="php-mysql is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748002" comment="php is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748012" comment="php-pgsql is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748004" comment="php-devel is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748006" comment="php-imap is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748008" comment="php-ldap is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748036" comment="php-gd is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748025" comment="php-odbc is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748023" comment="php-mysql is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748017" comment="php is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748030" comment="php-xmlrpc is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748032" comment="php-mbstring is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748024" comment="php-pgsql is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748018" comment="php-devel is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748034" comment="php-ncurses is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748026" comment="php-snmp is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748021" comment="php-imap is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748019" comment="php-pear is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748028" comment="php-domxml is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748022" comment="php-ldap is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050751" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:751: openldap and nss_ldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:751-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-751.html" />
          <reference source="CVE" ref_id="CVE-2004-0823" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0823.html" />
          <reference source="CVE" ref_id="CVE-2005-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2069.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

The nss_ldap module is an extension for use with GNU libc which allows
applications to, without internal modification, consult a directory service
using LDAP to supplement information that would be read from local files
such as /etc/passwd, /etc/group, and /etc/shadow.

A bug was found in the way OpenLDAP, nss_ldap, and pam_ldap refer LDAP
servers. If a client connection is referred to a different server, it is
possible that the referred connection will not be encrypted even if the
client has "ssl start_tls" in its ldap.conf file. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2069
to this issue.

A bug was also found in the way certain OpenLDAP authentication schemes
store hashed passwords. A remote attacker could re-use a hashed password to
gain access to unauthorized resources. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-0823 to this issue.

All users of OpenLDAP and nss_ldap are advised to upgrade to these updated
packages, which contain backported fixes that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2005-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0823.html">CVE-2004-0823</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2069.html">CVE-2005-2069</cve>
                <bugzilla href="http://bugzilla.redhat.com/156386" id="156386">CAN-2004-0823 openldap hashed password re-use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162482" id="162482">CAN-2005-2069 openldap password disclosure issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751004" comment="openldap-devel is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751005" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751008" comment="openldap-clients is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751009" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751002" comment="openldap is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751006" comment="openldap-servers is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751007" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751010" comment="nss_ldap is earlier than 0:207-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751011" comment="nss_ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050756" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:756: cvs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:756-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-756.html" />
          <reference source="CVE" ref_id="CVE-2005-2693" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2693.html" />
    
    <description>CVS (Concurrent Version System) is a version control system.

An insecure temporary file usage was found in the cvsbug program.  It is
possible that a local user could leverage this issue to execute arbitrary
instructions as the user running cvsbug.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2693 to this issue.

All users of cvs should upgrade to this updated package, which includes a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-06" />
        <updated date="2005-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2693.html">CVE-2005-2693</cve>
                <bugzilla href="http://bugzilla.redhat.com/166365" id="166365">CAN-2005-2693 CVS temporary file issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050756002" comment="cvs is earlier than 0:1.11.2-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050756005" comment="cvs is earlier than 0:1.11.17-8.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050761" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:761: pcre security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:761-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-761.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

An integer overflow flaw was found in PCRE, triggered by a maliciously
crafted regular expression.  On systems that accept arbitrary regular
expressions from untrusted users, this could be exploited to execute
arbitrary code with the privileges of the application using the library.
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2491 to this issue.

The security impact of this issue varies depending on the way that
applications make use of PCRE.  For example, the Apache web server uses the
system PCRE library in order to parse regular expressions, but this flaw
would only allow a user who already has the ability to write .htaccess
files to gain 'apache' privileges.  For applications supplied with Red Hat
Enterprise Linux, a maximum security impact of moderate has been assigned.

Users should update to these erratum packages that contain a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166330" id="166330">CAN-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761004" comment="pcre-devel is earlier than 0:3.9-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761002" comment="pcre is earlier than 0:3.9-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761008" comment="pcre-devel is earlier than 0:4.5-3.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761007" comment="pcre is earlier than 0:4.5-3.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050766" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:766: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:766-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-766.html" />
          <reference source="CVE" ref_id="CVE-2004-2479" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2479.html" />
          <reference source="CVE" ref_id="CVE-2005-2794" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2794.html" />
          <reference source="CVE" ref_id="CVE-2005-2796" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2796.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A bug was found in the way Squid displays error messages. A remote attacker
could submit a request containing an invalid hostname which would result in
Squid displaying a previously used error message. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-2479 to this issue.

Two denial of service bugs were found in the way Squid handles malformed
requests. A remote attacker could submit a specially crafted request to
Squid that would cause the server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-2794 and
CAN-2005-2796 to these issues.

Please note that CAN-2005-2796 does not affect Red Hat Enterprise Linux 2.1

Users of Squid should upgrade to this updated package that contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-15" />
        <updated date="2005-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2479.html">CVE-2004-2479</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2794.html">CVE-2005-2794</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2796.html">CVE-2005-2796</cve>
                <bugzilla href="http://bugzilla.redhat.com/166520" id="166520">CAN-2004-2479 squid information disclosure issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167413" id="167413">CAN-2005-2794 Multiple squid DoS issues (CAN-2005-2796)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050766002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050766005" comment="squid is earlier than 7:2.5.STABLE6-3.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050767" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:767: openldap and nss_ldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:767-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-767.html" />
          <reference source="CVE" ref_id="CVE-2005-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2069.html" />
          <reference source="CVE" ref_id="CVE-2005-2641" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2641.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

The nss_ldap module is an extension for use with GNU libc which allows
applications to, without internal modification, consult a directory service
using LDAP to supplement information that would be read from local files
such as /etc/passwd, /etc/group, and /etc/shadow.

A bug was found in the way OpenLDAP, nss_ldap, and pam_ldap refer LDAP
servers. If a client connection is referred to a different server, it is
possible that the referred connection will not be encrypted even if the
client has "ssl start_tls" in its ldap.conf file. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2069
to this issue.

A bug was found in the way the pam_ldap module processed certain failure
messages. If the server includes supplemental data in an authentication
failure result message, but the data does not include any specific error
code, the pam_ldap module would proceed as if the authentication request
had succeeded, and authentication would succeed. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-2641 to this issue. 

Additionally the following issues are corrected in this erratum.

- The OpenLDAP upgrading documentation has been updated.

- Fix a database deadlock locking issue.

- A fix where slaptest segfaults on exit after successful check.

- The library libslapd_db-4.2.so is now located in an
  architecture-dependent directory.

- The LDAP client no longer enters an infinite loop when the server returns
  a reference to itself.

- The pam_ldap module adds the ability to check user passwords using a
  directory server to PAM-aware applications.

- The directory server can now include supplemental information regarding
  the state of the user's account if a client indicates that it supports
  such a feature.

All users of OpenLDAP and nss_ldap are advised to upgrade to these updated
packages, which contain backported fixes that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2005-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2069.html">CVE-2005-2069</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2641.html">CVE-2005-2641</cve>
                <bugzilla href="http://bugzilla.redhat.com/159151" id="159151">Authconfig update creates a problem with OpenLDAP server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162482" id="162482">CAN-2005-2069 openldap password disclosure issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166163" id="166163">CAN-2005-2641 pam_ldap policy vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767004" comment="openldap-devel is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751005" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767010" comment="openldap-clients is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751009" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767008" comment="openldap-servers-sql is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050767009" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767012" comment="compat-openldap is earlier than 0:2.1.30-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050767013" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767002" comment="openldap is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767006" comment="openldap-servers is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751007" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767014" comment="nss_ldap is earlier than 0:226-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751011" comment="nss_ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050768" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:768: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:768-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-768.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox processes certain international domain
names. An attacker could create a specially crafted HTML file, which when
viewed by the victim would cause Firefox to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2871 to this issue. 

Users of Firefox are advised to upgrade to this updated package that
contains a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-09" />
        <updated date="2005-09-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/167930" id="167930">CAN-2005-2871 Firefox buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050768002" comment="firefox is earlier than 0:1.0.6-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050769" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:769: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:769-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-769.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla processes certain international domain
names. An attacker could create a specially crafted HTML file, which when
viewed by the victim would cause Mozilla to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2871 to this issue. 

Users of Mozilla are advised to upgrade to this updated package that
contains a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-09" />
        <updated date="2005-09-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/167934" id="167934">CAN-2005-2871 Mozilla buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769018" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769014" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769016" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769010" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769002" comment="mozilla is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769020" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769006" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769004" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769012" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769008" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769031" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769029" comment="mozilla-mail is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769030" comment="mozilla-chat is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769027" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769023" comment="mozilla is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769032" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769025" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769024" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769028" comment="mozilla-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769026" comment="mozilla-nss is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050771" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:771: wget security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:771-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-771.html" />
          <reference source="CVE" ref_id="CVE-2004-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1487.html" />
          <reference source="CVE" ref_id="CVE-2004-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1488.html" />
          <reference source="CVE" ref_id="CVE-2004-2014" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2014.html" />
    
    <description>GNU Wget is a file retrieval utility that can use either the HTTP or        
FTP protocols.       

A bug was found in the way wget writes files to the local disk. If a
malicious local user has write access to the directory wget is saving a
file into, it is possible to overwrite files that the user running wget
has write access to. (CAN-2004-2014)

A bug was found in the way wget filters redirection URLs. It is possible
for a malicious Web server to overwrite files the user running wget has
write access to. Note: in order for this attack to succeed the local
DNS would need to resolve ".." to an IP address, which is an unlikely
situation.  (CAN-2004-1487)

A bug was found in the way wget displays HTTP response codes. It is
possible that a malicious web server could inject a specially crafted
terminal escape sequence capable of misleading the user running wget.
(CAN-2004-1488)
   
Users should upgrade to this updated package, which contains a version of
wget that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1487.html">CVE-2004-1487</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1488.html">CVE-2004-1488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2014.html">CVE-2004-2014</cve>
                <bugzilla href="http://bugzilla.redhat.com/144214" id="144214">CAN-2004-1487 Several wget vulnerabilities (CAN-2004-1488)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157498" id="157498">CAN-2004-2014 wget symlink race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165782" id="165782">wget man page incomplete</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771002" comment="wget is earlier than 0:1.10.1-1.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771005" comment="wget is earlier than 0:1.10.1-2.4E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050772" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:772: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:772-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-772.html" />
          <reference source="CVE" ref_id="CVE-2005-2874" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2874.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A bug was found in the way CUPS processes malformed HTTP requests. It is
possible for a remote user capable of connecting to the CUPS daemon to
issue a malformed HTTP GET request that causes CUPS to enter an
infinite loop. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2874 to this issue.

Two small bugs have also been fixed in this update.  A signal handling
problem has been fixed that could occasionally cause the scheduler to stop
when told to reload.  A problem with tracking open file descriptors under
certain specific circumstances has also been fixed.

All users of CUPS should upgrade to these erratum packages, which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2874.html">CVE-2005-2874</cve>
                <bugzilla href="http://bugzilla.redhat.com/164641" id="164641">[PATCH] cupsd segfault when SIGCHLD received</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164642" id="164642">Cupsd hangs on reading pipe with recycled file descriptor.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168072" id="168072">CAN-2005-2874 Malformed HTTP Request URL denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772002" comment="cups is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050782" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:782: util-linux and mount security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:782-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-782.html" />
          <reference source="CVE" ref_id="CVE-2005-2876" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2876.html" />
          <reference source="CVE" ref_id="CVE-2001-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2001-1494.html" />
    
    <description>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function.

The mount package contains the mount, umount, swapon and swapoff programs.

A bug was found in the way the umount command is executed by normal users.
It may be possible for a user to gain elevated privileges if the user is
able to execute the "umount -r" command on a mounted file system. The
file system will be re-mounted only with the "readonly" flag set, clearing
flags such as "nosuid" and "noexec". The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2876 to
this issue.

This update also fixes a hardlink bug in the script command for Red Hat
Enterprise Linux 2.1. If a local user places a hardlinked file named
"typescript" in a directory they have write access to, the file will be
overwritten if the user running script has write permissions to the
destination file. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2001-1494 to this issue.

All users of util-linux and mount should upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2876.html">CVE-2005-2876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2001-1494.html">CVE-2001-1494</cve>
                <bugzilla href="http://bugzilla.redhat.com/161337" id="161337">CAN-2001-1494 hardlink vulnerability in 'script' command</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168206" id="168206">CAN-2005-2876 umount unsafe -r usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168209" id="168209">CAN-2005-2876 umount unsafe -r usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782002" comment="util-linux is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782004" comment="mount is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782005" comment="mount is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782006" comment="losetup is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782007" comment="losetup is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782009" comment="util-linux is earlier than 0:2.12a-16.EL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050785" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:785: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:785-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-785.html" />
          <reference source="CVE" ref_id="CVE-2005-2701" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2701.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-2968" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2968.html" />
          <reference source="CVE" ref_id="CVE-2005-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3089.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox processes XBM image files. If a user
views a specially crafted XBM file, it becomes possible to execute
arbitrary code as the user running Firefox. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2701 to
this issue.

A bug was found in the way Firefox processes certain Unicode
sequences. It may be possible to execute arbitrary code as the user running
Firefox if the user views a specially crafted Unicode sequence. (CAN-2005-2702)

A bug was found in the way Firefox makes XMLHttp requests. It is possible
that a malicious web page could leverage this flaw to exploit other proxy
or server flaws from the victim's machine. It is also possible that this
flaw could be leveraged to send XMLHttp requests to hosts other than the
originator; the default behavior of the browser is to disallow this.
(CAN-2005-2703)

A bug was found in the way Firefox implemented its XBL interface. It may be
possible for a malicious web page to create an XBL binding in such a way
that would allow arbitrary JavaScript execution with chrome permissions.
Please note that in Firefox 1.0.6 this issue is not directly exploitable
and will need to leverage other unknown exploits. (CAN-2005-2704)

An integer overflow bug was found in Firefox's JavaScript engine. Under
favorable conditions, it may be possible for a malicious web page to
execute arbitrary code as the user running Firefox. (CAN-2005-2705)

A bug was found in the way Firefox displays about: pages. It is possible
for a malicious web page to open an about: page, such as about:mozilla, in
such a way that it becomes possible to execute JavaScript with chrome
privileges. (CAN-2005-2706)

A bug was found in the way Firefox opens new windows. It is possible for a
malicious web site to construct a new window without any user interface
components, such as the address bar and the status bar. This window could
then be used to mislead the user for malicious purposes. (CAN-2005-2707)

A bug was found in the way Firefox processes URLs passed to it on the
command line. If a user passes a malformed URL to Firefox, such as clicking
on a link in an instant messaging program, it is possible to execute
arbitrary commands as the user running Firefox. (CAN-2005-2968)

Users of Firefox are advised to upgrade to this updated package that
contains Firefox version 1.0.7 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-22" />
        <updated date="2005-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2701.html">CVE-2005-2701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2968.html">CVE-2005-2968</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3089.html">CVE-2005-3089</cve>
                <bugzilla href="http://bugzilla.redhat.com/168527" id="168527">CAN-2005-2701 Multiple Firefox issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168740" id="168740">CAN-2005-2968 Firefox improper command line URL sanitization</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050785002" comment="firefox is earlier than 0:1.0.7-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050788" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:788: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:788-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-788.html" />
          <reference source="CVE" ref_id="CVE-2005-2629" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2629.html" />
          <reference source="CVE" ref_id="CVE-2005-2710" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2710.html" />
          <reference source="CVE" ref_id="CVE-2005-2922" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2922.html" />
    
    <description>HelixPlayer is a media player.

A format string bug was discovered in the way HelixPlayer processes RealPix
(.rp) files. It is possible for a malformed RealPix file to execute
arbitrary code as the user running HelixPlayer. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2710
to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.6 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2629.html">CVE-2005-2629</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2710.html">CVE-2005-2710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2922.html">CVE-2005-2922</cve>
                <bugzilla href="http://bugzilla.redhat.com/168078" id="168078">CAN-2005-2710 HelixPlayer Format String Flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050788002" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050789" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:789: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:789-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-789.html" />
          <reference source="CVE" ref_id="CVE-2005-2701" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2701.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3089.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla processes XBM image files. If a user
views a specially crafted XBM file, it becomes possible to execute
arbitrary code as the user running Mozilla. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2701 to
this issue.

A bug was found in the way Mozilla processes certain Unicode
sequences. It may be possible to execute arbitrary code as the user running
Mozilla, if the user views a specially crafted Unicode sequence.
(CAN-2005-2702)

A bug was found in the way Mozilla makes XMLHttp requests. It is possible
that a malicious web page could leverage this flaw to exploit other proxy
or server flaws from the victim's machine. It is also possible that this
flaw could be leveraged to send XMLHttp requests to hosts other than the
originator; the default behavior of the browser is to disallow this.
(CAN-2005-2703)

A bug was found in the way Mozilla implemented its XBL interface. It may be
possible for a malicious web page to create an XBL binding in a way
that would allow arbitrary JavaScript execution with chrome permissions.
Please note that in Mozilla 1.7.10 this issue is not directly exploitable
and would need to leverage other unknown exploits. (CAN-2005-2704)

An integer overflow bug was found in Mozilla's JavaScript engine. Under
favorable conditions, it may be possible for a malicious web page to
execute arbitrary code as the user running Mozilla. (CAN-2005-2705)

A bug was found in the way Mozilla displays about: pages. It is possible
for a malicious web page to open an about: page, such as about:mozilla, in
such a way that it becomes possible to execute JavaScript with chrome
privileges. (CAN-2005-2706)

A bug was found in the way Mozilla opens new windows. It is possible for a
malicious web site to construct a new window without any user interface
components, such as the address bar and the status bar. This window could
then be used to mislead the user for malicious purposes. (CAN-2005-2707)

Users of Mozilla are advised to upgrade to this updated package that
contains Mozilla version 1.7.12 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-22" />
        <updated date="2005-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2701.html">CVE-2005-2701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3089.html">CVE-2005-3089</cve>
                <bugzilla href="http://bugzilla.redhat.com/168525" id="168525">CAN-2005-2701 Multiple Mozilla issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789018" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789014" comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789016" comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789010" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789002" comment="mozilla is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789020" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789006" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789004" comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789012" comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789008" comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789031" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789029" comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789030" comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789027" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789023" comment="mozilla is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789032" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789025" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789024" comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789028" comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789026" comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789033" comment="devhelp is earlier than 0:0.9.2-2.4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050791" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:791: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:791-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-791.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-2968" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2968.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird processes certain international
domain names. An attacker could create a specially crafted HTML mail, which
when viewed by the victim would cause Thunderbird to crash or possibly
execute arbitrary code. Thunderbird as shipped with Red Hat Enterprise
Linux 4 must have international domain names enabled by the user in order
to be vulnerable to this issue. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2871 to this issue.

A bug was found in the way Thunderbird processes certain Unicode sequences.
It may be possible to execute arbitrary code as the user running
Thunderbird if the user views a specially crafted HTML mail containing
Unicode sequences. (CAN-2005-2702)

A bug was found in the way Thunderbird makes XMLHttp requests. It is
possible that a malicious HTML mail could leverage this flaw to exploit
other proxy or server flaws from the victim's machine. It is also possible
that this flaw could be leveraged to send XMLHttp requests to hosts other
than the originator; the default behavior of Thunderbird is to disallow
such actions. (CAN-2005-2703)

A bug was found in the way Thunderbird implemented its XBL interface. It
may be possible for a malicious HTML mail to create an XBL binding in such
a way that would allow arbitrary JavaScript execution with chrome
permissions. Please note that in Thunderbird 1.0.6 this issue is not
directly exploitable and will need to leverage other unknown exploits.
(CAN-2005-2704)

An integer overflow bug was found in Thunderbird's JavaScript engine. Under
favorable conditions, it may be possible for a malicious mail message to
execute arbitrary code as the user running Thunderbird. Please note that
JavaScript support is disabled by default in Thunderbird. (CAN-2005-2705)

A bug was found in the way Thunderbird displays about: pages. It is
possible for a malicious HTML mail to open an about: page, such as
about:mozilla, in such a way that it becomes possible to execute JavaScript
with chrome privileges. (CAN-2005-2706)

A bug was found in the way Thunderbird opens new windows. It is possible
for a malicious HTML mail to construct a new window without any user
interface components, such as the address bar and the status bar. This
window could then be used to mislead the user for malicious purposes.
(CAN-2005-2707)

A bug was found in the way Thunderbird processes URLs passed to it on the
command line. If a user passes a malformed URL to Thunderbird, such as
clicking on a link in an instant messaging program, it is possible to
execute arbitrary commands as the user running Thunderbird. (CAN-2005-2968) 

Users of Thunderbird are advised to upgrade to this updated package, which
contains Thunderbird version 1.0.7 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-06" />
        <updated date="2005-10-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2968.html">CVE-2005-2968</cve>
                <bugzilla href="http://bugzilla.redhat.com/167944" id="167944">CAN-2005-2871 Firefox buffer overflow affects thunderbird</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168531" id="168531">CAN-2005-2701 Multiple Firefox issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050791002" comment="thunderbird is earlier than 0:1.0.7-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050793" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:793: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:793-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-793.html" />
          <reference source="CVE" ref_id="CVE-2005-2978" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2978.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts Portable Anymap (PNM) files into
Portable Network Graphics (PNG). The usage of uninitialised variables in
the pnmtopng code allows an attacker to change stack contents when
converting to PNG files with pnmtopng using the '-trans' option. This may
allow an attacker to execute arbitrary code. The Common Vulnerabilities
and Exposures project assigned the name CAN-2005-2978 to this issue.

All users of netpbm should upgrade to the updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-18" />
        <updated date="2005-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2978.html">CVE-2005-2978</cve>
                <bugzilla href="http://bugzilla.redhat.com/168278" id="168278">CAN-2005-2978 Crash running pnmtopng -trans on some pnm files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793002" comment="netpbm is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793004" comment="netpbm-devel is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793006" comment="netpbm-progs is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050799" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:799: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:799-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-799.html" />
          <reference source="CVE" ref_id="CVE-2005-2337" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2337.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A bug was found in the way ruby handles eval statements. It is possible for
a malicious script to call eval in such a way that can allow the bypass of
certain safe-level restrictions. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2337 to this issue.

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2337.html">CVE-2005-2337</cve>
                <bugzilla href="http://bugzilla.redhat.com/169575" id="169575">CAN-2005-2337 ruby safe-level mode bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799010" comment="irb is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799002" comment="ruby is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799022" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799021" comment="irb is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799023" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799020" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799018" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799017" comment="ruby is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799019" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050800" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:800: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:800-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-800.html" />
          <reference source="CVE" ref_id="CVE-2005-2969" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2969.html" />
          <reference source="CVE" ref_id="CVE-2005-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0109.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

OpenSSL contained a software work-around for a bug in SSL handling in
Microsoft Internet Explorer version 3.0.2. This work-around is enabled in
most servers that use OpenSSL to provide support for SSL and TLS. Yutaka
Oiwa discovered that this work-around could allow an attacker, acting as a
"man in the middle" to force an SSL connection to use SSL 2.0 rather than a
stronger protocol such as SSL 3.0 or TLS 1.0. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2969
to this issue.

A bug was also fixed in the way OpenSSL creates DSA signatures. A cache
timing attack was fixed in RHSA-2005-476 which caused OpenSSL to do private
key calculations with a fixed time window. The DSA fix for this was not
complete and the calculations are not always performed within a
fixed-window. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0109 to this issue.

Users are advised to upgrade to these updated packages, which remove the
MISE 3.0.2 work-around and contain patches to correct these issues.

Note: After installing this update, users are advised to either
restart all services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2969.html">CVE-2005-2969</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0109.html">CVE-2005-0109</cve>
                <bugzilla href="http://bugzilla.redhat.com/169863" id="169863">CAN-2005-2969 Potential SSL 2.0 Rollback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170036" id="170036">CAN-2005-0109 DSA signing not quite constant time</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800002" comment="openssl096b is earlier than 0:0.9.6b-16.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800004" comment="openssl is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800008" comment="openssl-perl is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800006" comment="openssl-devel is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800011" comment="openssl096b is earlier than 0:0.9.6b-22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800012" comment="openssl is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800014" comment="openssl-perl is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800013" comment="openssl-devel is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050802" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:802: xloadimage security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:802-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-802.html" />
          <reference source="CVE" ref_id="CVE-2005-3178" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3178.html" />
    
    <description>The xloadimage utility displays images in an X Window System window, loads
images into the root window, or writes images into a file.  Xloadimage
supports many image types (including GIF, TIFF, JPEG, XPM, and XBM).

A flaw was discovered in xloadimage via which an attacker can construct a
NIFF image with a very long embedded image title. This image can cause a
buffer overflow. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-3178 to this issue.

All users of xloadimage should upgrade to this erratum package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-18" />
        <updated date="2005-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3178.html">CVE-2005-3178</cve>
                <bugzilla href="http://bugzilla.redhat.com/170150" id="170150">CAN-2005-3178 xloadimage NIFF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050802002" comment="xloadimage is earlier than 0:4.1-36.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050802005" comment="xloadimage is earlier than 0:4.1-36.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050803" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:803: lynx security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:803-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-803.html" />
          <reference source="CVE" ref_id="CVE-2005-3120" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3120.html" />
    
    <description>Lynx is a text-based Web browser. 

Ulf Härnhammar discovered a stack overflow bug in Lynx when handling
connections to NNTP (news) servers.  An attacker could create a web page
redirecting to a malicious news server which could execute arbitrary code
as the user running lynx.  The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-3120 to this issue.

Users should update to this erratum package, which contains a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3120.html">CVE-2005-3120</cve>
                <bugzilla href="http://bugzilla.redhat.com/170253" id="170253">CAN-2005-3120 lynx buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803002" comment="lynx is earlier than 0:2.8.5-11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803005" comment="lynx is earlier than 0:2.8.5-18.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050805" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:805: pam security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:805-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-805.html" />
          <reference source="CVE" ref_id="CVE-2005-2977" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2977.html" />
    
    <description>PAM (Pluggable Authentication Modules) is a system security tool that
allows system administrators to set an authentication policy without
having to recompile programs that handle authentication.

A bug was found in the way PAM's unix_chkpwd helper program validates user
passwords when SELinux is enabled. Under normal circumstances, it is not
possible for a local non-root user to verify the password of another local
user with the unix_chkpwd command. A patch applied that adds SELinux
functionality makes it possible for a local user to use brute force
password guessing techniques against other local user accounts. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2005-2977 to
this issue.

All users of pam should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-26" />
        <updated date="2005-10-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2977.html">CVE-2005-2977</cve>
                <bugzilla href="http://bugzilla.redhat.com/168181" id="168181">CVE-2005-2977 unix_chkpwd helper doesn't verify requesting user if SELinux is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050805004" comment="pam-devel is earlier than 0:0.77-66.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050805005" comment="pam-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050805002" comment="pam is earlier than 0:0.77-66.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050805003" comment="pam is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050807" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:807: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:807-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-807.html" />
          <reference source="CVE" ref_id="CVE-2005-3185" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3185.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols.

A stack based buffer overflow bug was found in cURL's NTLM authentication
module. It is possible to execute arbitrary code on a user's machine if
the user can be tricked into connecting to a malicious web server using
NTLM authentication. The Common Vulnerabilities and Exposures project
has assigned the name CVE-2005-3185 to this issue.

All users of curl are advised to upgrade to these updated packages, which
contain a backported patch that resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-02" />
        <updated date="2005-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3185.html">CVE-2005-3185</cve>
                <bugzilla href="http://bugzilla.redhat.com/170678" id="170678">CAN-2005-3185 NTLM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807002" comment="curl is earlier than 0:7.10.6-7.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807004" comment="curl-devel is earlier than 0:7.10.6-7.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807007" comment="curl is earlier than 0:7.12.1-6.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807008" comment="curl-devel is earlier than 0:7.12.1-6.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050808" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:808: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:808-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-808.html" />
          <reference source="CVE" ref_id="CVE-2005-3053" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3053.html" />
          <reference source="CVE" ref_id="CVE-2005-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3108.html" />
          <reference source="CVE" ref_id="CVE-2005-3110" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3110.html" />
          <reference source="CVE" ref_id="CVE-2005-3119" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3119.html" />
          <reference source="CVE" ref_id="CVE-2005-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3180.html" />
          <reference source="CVE" ref_id="CVE-2005-3181" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3181.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

An issue was discovered that affects how page attributes are changed by the
kernel.  Video drivers, which sometimes map kernel pages with a different
caching policy than write-back, are now expected to function correctly. 
This change affects the x86, AMD64, and Intel EM64T architectures.

In addition the following security bugs were fixed:

The set_mempolicy system call did not check for negative numbers in the
policy field.  An unprivileged local user could use this flaw to cause a
denial of service (system panic).  (CVE-2005-3053)

A flaw in ioremap handling on AMD 64 and Intel EM64T systems.  An
unprivileged local user could use this flaw to cause a denial of service or
minor information leak. (CVE-2005-3108)

A race condition in the ebtables netfilter module.  On a SMP system that is
operating under a heavy load this flaw may allow remote attackers to cause
a denial of service (crash).  (CVE-2005-3110)

A memory leak was found in key handling.  An unprivileged local user could
use this flaw to cause a denial of service. (CVE-2005-3119)

A flaw in the Orinoco wireless driver.  On systems running the vulnerable
drive, a remote attacker could send carefully crafted packets which would
divulge the contents of uninitialized kernel memory.  (CVE-2005-3180)

A memory leak was found in the audit system.  An unprivileged local user
could use this flaw to cause a denial of service.  (CVE-2005-3181)

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-27" />
        <updated date="2005-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3053.html">CVE-2005-3053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3108.html">CVE-2005-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3110.html">CVE-2005-3110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3119.html">CVE-2005-3119</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3180.html">CVE-2005-3180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3181.html">CVE-2005-3181</cve>
                <bugzilla href="http://bugzilla.redhat.com/108616" id="108616">RHEL4 (IPF): Support for Additional function in Intel's Monticeto processor (HW)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108827" id="108827">RHEL4:  Infiniband support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131889" id="131889">RHEL4 U2: SATA ATAPI support (including ESB2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139949" id="139949">sym driver creates voluminous /var/log/messages entries</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141699" id="141699">FEAT: RHEL 4 U3: ia64 needs hint@pause in spinloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141851" id="141851">spin loops on both ia32 and ia32e need cpu_relax</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144477" id="144477">bonding mode=6 + dhcp doesn't work correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144703" id="144703">ia32 apps that are not large file aware can access files >= 4GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145061" id="145061">SMART support in SATA driver (P1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149294" id="149294">qlogic fabric rediscovery functionality missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150893" id="150893">On few Nocona based platforms, acpi-cpufreq driver assumes the wrong CPU freq at boot time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151549" id="151549">RHEL 4 Kernel does not provide ACL support over NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152036" id="152036">Amanda hangs on backup in case of ip_conntrack_amanda is used (RHEL4)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153971" id="153971">large usb flash drive require reboot to mount more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154387" id="154387">umount fails on nfs server side when nfs client does heavy io</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155017" id="155017">Unisys' x86_64 ES7000 loses legacy devices during boot when using latest ES7000 platform code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156437" id="156437">Writing large file to 1TB ext3 volume sometimes very slow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156602" id="156602">SCTP memory consumption, additional fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156785" id="156785">Missing SHUTDOWN notification with SCTP stream socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157241" id="157241">[RHEL4-U3] PCI Hotplug - Slot powered off after enabling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157586" id="157586">ES7000 systems won't boot with large configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158861" id="158861">CVE-2004-1190 Continued raw access issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159869" id="159869">Diskdump fails through ipr driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160308" id="160308">USB Key stops working after upgrade to U1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160844" id="160844">dangling POSIX locks after close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161362" id="161362">Oracle Hangs with directio and aio using NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161597" id="161597">sysfs_remove_dir() de-references NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161617" id="161617">RHEL4 Panics at smp_apic_timer_interrupt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161846" id="161846">Problem with b44: SIOCSIFFLAGS: Cannot allocate memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162094" id="162094">read() with count > 0xffffffff panics kernel at fs/direct-io.c:886</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162731" id="162731">[RHEL4] 'getpriority/setpriority'  broken with PRIO_USER, who=0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162732" id="162732">io_cancel doesn't work properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162814" id="162814">Assertion failure in log_do_checkpoint</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163150" id="163150">request backport of fc transport class HBA port_id for dm-multipath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163738" id="163738">Kernel PANIC - not syncing: fatal exception</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163741" id="163741">qetharp 'Operation not supported' on non-layer2 guestlan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164298" id="164298">PANIC at rpc_wake_up_status</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164547" id="164547">Bug in IPv6 address adding error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165018" id="165018">Bonding driver fails to switch to backup link</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165092" id="165092">Bugs in kernel key managment syscall interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165154" id="165154">Bad order for release_region in error exit from i810_probe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165679" id="165679">CVE-2005-2458 gzip/zlib flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165741" id="165741">acct does not have Large File Support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165744" id="165744">2.6: /sbin/service iptables stop hangs on modprobe -r ipt_state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165959" id="165959">NFS/RPC - timestamp conversion is wrong</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166454" id="166454">rpmbuild --rebuild glibc-2.3.4-2.12.src.rpm hangs (same problem with glibc-2.3.4-2.9.src.rpm)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166524" id="166524">Erratic behaviour when system fd limit reached</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166589" id="166589">mount/umount can cause the block device reads to fail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166880" id="166880">[RHEL4 U1] OOPS removing ahci driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167115" id="167115">[RHEL4 U1] Bonding driver does not switch to backup interface upon active interface failure under heavy UDP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167192" id="167192">NFSv3 locking misses important kernel patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167211" id="167211">RHEL4 Panic in __wake_up_common (networking)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167630" id="167630">Multicast domain membership doesn't follow bonding failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167634" id="167634">RHEL4 __copy_user breaks on unaligned src</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167645" id="167645">RHEL4 U2 performance regression running enterprise workload</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167696" id="167696">CVE-2005-2800 SCSI proc DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167730" id="167730">FEAT RHEL4 U3: 10GigE Neterion Driver Update (S2io)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167731" id="167731">[RHEL4] hangcheck-timer not compiled in RHEL4 on IA64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167907" id="167907">SCTP association restart problem, possible backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168090" id="168090">ipmi_poweroff driver update for Dell &lt;8G servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168262" id="168262">[RHEL4 U1][diskdump] Diskdump from OS_INIT fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168431" id="168431">autofs removes leading path components of /net mounts on timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168483" id="168483">FEAT: [RHEL4 U3] kernel dm: Statistic information about dm devices (*)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168659" id="168659">CVE-2005-3044 lost fput and sockfd_put could lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168775" id="168775">wait() and waitpid() return inconsistencies under high load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168777" id="168777">CVE-2005-3276 sys_get_thread_area minor info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168824" id="168824">[FEAT:][RHEL 4 U3]LVM2 Snapshot support of root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168924" id="168924">CVE-2005-2709 More sysctl flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169042" id="169042">[Texas Instruments] nfs bindresvport: Address already in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169130" id="169130">CVE-2005-3356 double decrement of mqueue_mnt->mnt_count in sys_mq_open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169149" id="169149">oops in gss_pipe_release()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169184" id="169184">ls hangs on krb5 mountd when user has not kinit-ed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169197" id="169197">NFS client oops when debugging is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170146" id="170146">CRM648268: kernel reporting init process cutime as very large negative value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170262" id="170262">CVE-2005-3106 exec_mmap race DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170423" id="170423">Cache invalidation bug in nfs v3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170487" id="170487">Bad: kernel panic on boot (kernel-2.6.9-22.EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170546" id="170546">kernel_lock() problem through NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170656" id="170656">iSCSI connection recovery uses session address instead of portal address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170864" id="170864">device-mapper mirroring backwards compatibility issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170887" id="170887">Neterion(S2io) adapter not functional after running offline diagnostics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171002" id="171002">CVE-2005-3109 HFS oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171112" id="171112">Kernel oops killing process with open files on a NFS3 krb5 mount after /var/lib/nfs/rpc_pipefs has been unmounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171141" id="171141">FEAT RHEL4 U3 [diskdump]: kernel - support compressing dump data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171220" id="171220">USB: khubd deadlock on error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171705" id="171705">Kernel key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171715" id="171715">nfsd: clear signals before exiting the nfsd() thread</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171765" id="171765">linux-2.6.13-key-reiserfs.patch is incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171950" id="171950">Can't reboot on IBM xSeries 236.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171989" id="171989">rhel4 modules loading signing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172081" id="172081">rename(2) onto an empty directory fails on NFS file systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172214" id="172214">Large LUNS can't be seen with Hitachi Open-L SAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172487" id="172487">Difficulty with some iSCSI targets in iscsi_sfnet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172595" id="172595">netpoll can dereference a null pointer, causing a system crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172598" id="172598">[RHEL4] tuxstat SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172892" id="172892">kernel dm: dm-ioctl memory leak on attempt to load non-existing mapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172986" id="172986">autofs doesn't remount if nfs server is unreachable at expire time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173155" id="173155">kernel dm: DM_LIST_VERSIONS_CMD ioctl reponse truncated</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173156" id="173156">kernel dm: Notify userspace when a device is renamed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173157" id="173157">kernel dm-log: big endian 64-bit corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173158" id="173158">kernel dm-log: Make mirror log arch-independent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173159" id="173159">kernel dm: move bdget outside lockfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173161" id="173161">kernel dm: Make lock_fs optional.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173163" id="173163">kernel dm snapshot: Separate out metadata reading.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173164" id="173164">kernel dm snapshot: Load metadata on table creation not resumption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173166" id="173166">kernel dm snapshot: Reduce PF_MEMALLOC usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173174" id="173174">kernel dm multipath: Fix do_end_io locking.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173194" id="173194">race condition when expiring ghosted autofs mounts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173206" id="173206">kernel dm snapshot: bio_list_merge fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173304" id="173304">Fix for SystemTap bugzilla #1345 - return probe on do_execve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173354" id="173354">unable to create sgi_sn/ptc_statistics" printed to the console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173486" id="173486">Further key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173493" id="173493">Permit key management to request already running process to instantiate a key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173981" id="173981">kernel bug at mm/prio_tree.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808002" comment="kernel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808006" comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808004" comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808010" comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808012" comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808008" comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050809" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:809: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:809-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-809.html" />
          <reference source="CVE" ref_id="CVE-2005-3241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3241.html" />
          <reference source="CVE" ref_id="CVE-2005-3242" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3242.html" />
          <reference source="CVE" ref_id="CVE-2005-3243" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3243.html" />
          <reference source="CVE" ref_id="CVE-2005-3244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3244.html" />
          <reference source="CVE" ref_id="CVE-2005-3245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3245.html" />
          <reference source="CVE" ref_id="CVE-2005-3246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3246.html" />
          <reference source="CVE" ref_id="CVE-2005-3247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3247.html" />
          <reference source="CVE" ref_id="CVE-2005-3248" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3248.html" />
          <reference source="CVE" ref_id="CVE-2005-3249" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3249.html" />
          <reference source="CVE" ref_id="CVE-2005-3184" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3184.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code. The Common Vulnerabilities and Exposures project
has assigned the names CVE-2005-3241, CVE-2005-3242, CVE-2005-3243,
CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248,
CVE-2005-3249, and CVE-2005-3184 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.13 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-25" />
        <updated date="2005-10-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3241.html">CVE-2005-3241</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3242.html">CVE-2005-3242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3243.html">CVE-2005-3243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3244.html">CVE-2005-3244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3245.html">CVE-2005-3245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3246.html">CVE-2005-3246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3247.html">CVE-2005-3247</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3248.html">CVE-2005-3248</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3249.html">CVE-2005-3249</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3184.html">CVE-2005-3184</cve>
                <bugzilla href="http://bugzilla.redhat.com/171062" id="171062">CVE-2005-3241 Multiple ethereal issues (CVE-2005-3242 CVE-2005-3243 CVE-2005-3244 CVE-2005-3245 CVE-2005-3246 CVE-2005-3247 CVE-2005-3248 CVE-2005-3249 CVE-2005-3184)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809004" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809002" comment="ethereal is earlier than 0:0.10.13-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809008" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809007" comment="ethereal is earlier than 0:0.10.13-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050810" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:810: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:810-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-810.html" />
          <reference source="CVE" ref_id="CVE-2005-3186" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3186.html" />
          <reference source="CVE" ref_id="CVE-2005-2976" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2976.html" />
          <reference source="CVE" ref_id="CVE-2005-2975" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2975.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes XPM images. An attacker
could create a carefully crafted XPM file in such a way that it could cause
an application linked with gdk-pixbuf to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an integer overflow bug in the way gdk-pixbuf
processes XPM images. An attacker could create a carefully crafted XPM file
in such a way that it could cause an application linked with gdk-pixbuf to
execute arbitrary code or crash when the file was opened by a victim. The
Common Vulnerabilities and Exposures project has assigned the name
CVE-2005-2976 to this issue.

Ludwig Nussel also discovered an infinite-loop denial of service bug in the
way gdk-pixbuf processes XPM images. An attacker could create a carefully
crafted XPM file in such a way that it could cause an application linked
with gdk-pixbuf to stop responding when the file was opened by a victim.
The Common Vulnerabilities and Exposures project has assigned the name
CVE-2005-2975 to this issue.

Users of gdk-pixbuf are advised to upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-15" />
        <updated date="2005-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3186.html">CVE-2005-3186</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2976.html">CVE-2005-2976</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2975.html">CVE-2005-2975</cve>
                <bugzilla href="http://bugzilla.redhat.com/171071" id="171071">CVE-2005-3186 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171900" id="171900">CVE-2005-2975 Multiple XPM processing issues (CVE-2005-2976)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810002" comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810009" comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050811" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:811: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:811-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-811.html" />
          <reference source="CVE" ref_id="CVE-2005-3186" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3186.html" />
          <reference source="CVE" ref_id="CVE-2005-2975" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2975.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System.

A bug was found in the way gtk2 processes XPM images. An attacker could
create a carefully crafted XPM file in such a way that it could cause an
application linked with gtk2 to execute arbitrary code when the file was
opened by a victim. The Common Vulnerabilities and Exposures project has
assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an infinite-loop denial of service bug in the way
gtk2 processes XPM images. An attacker could create a carefully crafted XPM
file in such a way that it could cause an application linked with gtk2 to
stop responding when the file was opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2005-2975
to this issue.

Users of gtk2 are advised to upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-15" />
        <updated date="2005-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3186.html">CVE-2005-3186</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2975.html">CVE-2005-2975</cve>
                <bugzilla href="http://bugzilla.redhat.com/171073" id="171073">CVE-2005-3186 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171904" id="171904">CVE-2005-2975 gtk2 XPM DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811002" comment="gtk2 is earlier than 0:2.2.4-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811004" comment="gtk2-devel is earlier than 0:2.2.4-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811007" comment="gtk2 is earlier than 0:2.4.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811008" comment="gtk2-devel is earlier than 0:2.4.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050812" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:812: wget security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:812-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-812.html" />
          <reference source="CVE" ref_id="CVE-2005-3185" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3185.html" />
    
    <description>GNU Wget is a file retrieval utility that can use either the HTTP or
FTP protocols.

A stack based buffer overflow bug was found in the wget implementation of
NTLM authentication.  An attacker could execute arbitrary code on a user's
machine if the user can be tricked into connecting to a malicious web
server using NTLM authentication. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-3185 to this issue.

All users of wget are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-03" />
        <updated date="2005-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3185.html">CVE-2005-3185</cve>
                <bugzilla href="http://bugzilla.redhat.com/170666" id="170666">CVE-2005-3185 NTLM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050812002" comment="wget is earlier than 0:1.10.2-0.30E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050812005" comment="wget is earlier than 0:1.10.2-0.40E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050825" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:825: lm_sensors security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:825-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-825.html" />
          <reference source="CVE" ref_id="CVE-2005-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2672.html" />
    
    <description>The lm_sensors package includes a collection of modules for general SMBus
access and hardware monitoring. This package requires special support which
is not in standard version 2.2 kernels.

A bug was found in the way the pwmconfig tool creates temporary files. It
is possible that a local attacker could leverage this flaw to overwrite
arbitrary files located on the system. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-2672 to this issue.

Users of lm_sensors are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-10" />
        <updated date="2005-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2672.html">CVE-2005-2672</cve>
                <bugzilla href="http://bugzilla.redhat.com/166672" id="166672">CVE-2005-2672 lm_sensors pwmconfig insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050825004" comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050825005" comment="lm_sensors-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050825002" comment="lm_sensors is earlier than 0:2.8.7-2.40.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050825003" comment="lm_sensors is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050828" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:828: libungif security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:828-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-828.html" />
          <reference source="CVE" ref_id="CVE-2005-2974" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2974.html" />
          <reference source="CVE" ref_id="CVE-2005-3350" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3350.html" />
    
    <description>The libungif package contains a shared library of functions for loading and
saving GIF format image files.

Several bugs in the way libungif decodes GIF images were discovered. An
attacker could create a carefully crafted GIF image file in such a way that
it could cause an application linked with libungif to crash or execute
arbitrary code when the file is opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the names CVE-2005-2974
and CVE-2005-3350 to these issues.

All users of libungif are advised to upgrade to these updated packages,
which contain backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-03" />
        <updated date="2005-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2974.html">CVE-2005-2974</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3350.html">CVE-2005-3350</cve>
                <bugzilla href="http://bugzilla.redhat.com/171413" id="171413">CVE-2005-2974 Several libungif issues (CVE-2005-3350)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828002" comment="libungif is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828003" comment="libungif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828006" comment="libungif-progs is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828007" comment="libungif-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828004" comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828005" comment="libungif-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828009" comment="libungif is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828003" comment="libungif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828011" comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828007" comment="libungif-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828010" comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828005" comment="libungif-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050830" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:830: openssl096b security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:830-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-830.html" />
          <reference source="CVE" ref_id="CVE-2004-0079" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0079.html" />
    
    <description>The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),
Transport Layer Security (TLS v1) protocols, and serves as a full-strength
general purpose cryptography library. OpenSSL 0.9.6b libraries are provided
for Red Hat Enterprise Linux 3 and 4 to allow compatibility with legacy
applications.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a null-pointer assignment in the do_change_cipher_spec()
function.  A remote attacker could perform a carefully crafted SSL/TLS
handshake against a server that uses the OpenSSL library in such a way as
to cause OpenSSL to crash.  Depending on the server this could lead to a
denial of service.  (CVE-2004-0079)

This issue was reported as not affecting OpenSSL versions prior to 0.9.6c,
and testing with the Codenomicon Test Tool showed that OpenSSL 0.9.6b as
shipped as a compatibility library with Red Hat Enterprise Linux 3 and 4
did not crash.  However, an alternative reproducer has been written which
shows that this issue does affect versions of OpenSSL prior to 0.9.6c.

Note that Red Hat does not ship any applications with Red Hat Enterprise
Linux 3 or 4 that use these compatibility libraries.  

Users of the OpenSSL096b compatibility package are advised to upgrade to
these updated packages, which contain a patch provided by the OpenSSL group
that protect against this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-02" />
        <updated date="2005-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0079.html">CVE-2004-0079</cve>
                <bugzilla href="http://bugzilla.redhat.com/172094" id="172094">CVE-2004-0079 OpenSSL remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050830002" comment="openssl096b is earlier than 0:0.9.6b-16.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050830005" comment="openssl096b is earlier than 0:0.9.6b-22.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050831" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:831: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:831-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-831.html" />
          <reference source="CVE" ref_id="CVE-2005-3353" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3353.html" />
          <reference source="CVE" ref_id="CVE-2005-3388" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3388.html" />
          <reference source="CVE" ref_id="CVE-2005-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3389.html" />
          <reference source="CVE" ref_id="CVE-2005-3390" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3390.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A flaw was found in the way PHP registers global variables during a file
upload request.  A remote attacker could submit a carefully crafted
multipart/form-data POST request that would overwrite the $GLOBALS array,
altering expected script behavior, and possibly leading to the execution of
arbitrary PHP commands.  Please note that this vulnerability only affects
installations which have register_globals enabled in the PHP configuration
file, which is not a default or recommended option.  The Common
Vulnerabilities and Exposures project assigned the name CVE-2005-3390 to
this issue.

A flaw was found in the PHP parse_str() function. If a PHP script passes
only one argument to the parse_str() function, and the script can be forced
to abort execution during operation (for example due to the memory_limit
setting), the register_globals may be enabled even if it is disabled in the
PHP configuration file.  This vulnerability only affects installations that
have PHP scripts using the parse_str function in this way.  (CVE-2005-3389)

A Cross-Site Scripting flaw was found in the phpinfo() function. If a
victim can be tricked into following a malicious URL to a site with a page
displaying the phpinfo() output, it may be possible to inject javascript
or HTML content into the displayed page or steal data such as cookies. 
This vulnerability only affects installations which allow users to view the
output of the phpinfo() function.  As the phpinfo() function outputs a
large amount of information about the current state of PHP, it should only
be used during debugging or if protected by authentication.  (CVE-2005-3388)

A denial of service flaw was found in the way PHP processes EXIF image
data.  It is possible for an attacker to cause PHP to crash by supplying
carefully crafted EXIF image data. (CVE-2005-3353)

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-10" />
        <updated date="2005-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3353.html">CVE-2005-3353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3388.html">CVE-2005-3388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3389.html">CVE-2005-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3390.html">CVE-2005-3390</cve>
                <bugzilla href="http://bugzilla.redhat.com/172207" id="172207">CVE-2005-3390 PHP register globals arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172209" id="172209">CVE-2005-3389 PHP parse_str can enable register_globals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172212" id="172212">CVE-2005-3388 PHP phpinfo() XSS attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172589" id="172589">CVE-2005-3353 PHP exif data DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831014" comment="php-odbc is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831010" comment="php-mysql is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831002" comment="php is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831012" comment="php-pgsql is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831004" comment="php-devel is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831006" comment="php-imap is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831008" comment="php-ldap is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831036" comment="php-gd is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831025" comment="php-odbc is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831023" comment="php-mysql is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831017" comment="php is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831030" comment="php-xmlrpc is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831032" comment="php-mbstring is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831024" comment="php-pgsql is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831018" comment="php-devel is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831034" comment="php-ncurses is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831026" comment="php-snmp is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831021" comment="php-imap is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831019" comment="php-pear is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831028" comment="php-domxml is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831022" comment="php-ldap is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050839" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:839: lynx security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-839.html" />
          <reference source="CVE" ref_id="CVE-2005-2929" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2929.html" />
    
    <description>Lynx is a text-based Web browser.

An arbitrary command execute bug was found in the lynx "lynxcgi:" URI
handler. An attacker could create a web page redirecting to a malicious URL
which could execute arbitrary code as the user running lynx. The Common
Vulnerabilities and Exposures project assigned the name CVE-2005-2929 to
this issue.

Users should update to this erratum package, which contains a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-11" />
        <updated date="2005-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2929.html">CVE-2005-2929</cve>
                <bugzilla href="http://bugzilla.redhat.com/172972" id="172972">CVE-2005-2929 lynx arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050839002" comment="lynx is earlier than 0:2.8.5-11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050839005" comment="lynx is earlier than 0:2.8.5-18.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050840" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:840: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:840-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-840.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

Several flaws were discovered in Xpdf.  An attacker could construct a
carefully crafted PDF file that could cause Xpdf to crash or possibly
execute arbitrary code when opened.  The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of Xpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.

Red Hat would like to thank Derek B. Noonburg for reporting this issue and
providing a patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/173888" id="173888">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050840002" comment="xpdf is earlier than 1:2.02-9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050840005" comment="xpdf is earlier than 1:3.00-11.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050843" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:843: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:843-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-843.html" />
          <reference source="CVE" ref_id="CVE-2005-3632" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3632.html" />
          <reference source="CVE" ref_id="CVE-2005-3662" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3662.html" />
    
    <description>The netpbm package contains a library of functions that support programs
for handling various graphics file formats.

A stack based buffer overflow bug was found in the way netpbm converts
Portable Anymap (PNM) files into Portable Network Graphics (PNG). A
specially crafted PNM file could allow an attacker to execute arbitrary
code by attempting to convert a PNM file to a PNG file when using pnmtopng
with the '-text' option. The Common Vulnerabilities and Exposures project
has assigned the name CVE-2005-3632 to this issue.

An "off by one" bug was found in the way netpbm converts Portable Anymap
(PNM) files into Portable Network Graphics (PNG). If a victim attempts to
convert a specially crafted 256 color PNM file to a PNG file, then it can
cause the pnmtopng utility to crash. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-3662 to this issue.

All users of netpbm should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3632.html">CVE-2005-3632</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3662.html">CVE-2005-3662</cve>
                <bugzilla href="http://bugzilla.redhat.com/173342" id="173342">CVE-2005-3662 netpbm off by one error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173344" id="173344">CVE-2005-3632 Netpbm buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843002" comment="netpbm is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843004" comment="netpbm-devel is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843006" comment="netpbm-progs is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050848" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:848: libc-client security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:848-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-848.html" />
          <reference source="CVE" ref_id="CVE-2005-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2933.html" />
    
    <description>C-client is a common API for accessing mailboxes.

A buffer overflow flaw was discovered in the way C-client parses user
supplied mailboxes. If an authenticated user requests a specially crafted
mailbox name, it may be possible to execute arbitrary code on a server that
uses C-client to access mailboxes. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-2933 to this issue.

All users of libc-client should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2933.html">CVE-2005-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/171344" id="171344">CVE-2005-2933 imap buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050848002" comment="libc-client is earlier than 0:2002e-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050848003" comment="libc-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050848004" comment="libc-client-devel is earlier than 0:2002e-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050848005" comment="libc-client-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050850" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:850: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:850-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-850.html" />
          <reference source="CVE" ref_id="CVE-2005-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2933.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access protocols.

A buffer overflow flaw was discovered in the way the c-client library
parses user supplied mailboxes. If an authenticated user requests a
specially crafted mailbox name, it may be possible to execute arbitrary
code on a server that uses the library. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-2933 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2933.html">CVE-2005-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/169953" id="169953">CVE-2005-2933 imap buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850006" comment="imap-utils is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850004" comment="imap-devel is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850002" comment="imap is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050864" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:864: udev security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:864-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-864.html" />
          <reference source="CVE" ref_id="CVE-2005-3631" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3631.html" />
    
    <description>The udev package contains an implementation of devfs in userspace using
sysfs and /sbin/hotplug.

Richard Cunningham discovered a flaw in the way udev sets permissions on
various files in /dev/input. It may be possible for an authenticated
attacker to gather sensitive data entered by a user at the console, such as
passwords. The Common Vulnerabilities and Exposures project has assigned
the name CVE-2005-3631 to this issue.

All users of udev should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3631.html">CVE-2005-3631</cve>
                <bugzilla href="http://bugzilla.redhat.com/174845" id="174845">CVE-2005-3631 /dev/input/* incorrect permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050864002" comment="udev is earlier than 0:039-10.10.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050864003" comment="udev is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050867" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:867: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:867-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-867.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The gpdf package is a GNOME based viewer for Portable Document Format
(PDF) files.

Several flaws were discovered in gpdf. An attacker could construct a
carefully crafted PDF file that could cause gpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175100" id="175100">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050867002" comment="gpdf is earlier than 0:2.8.2-7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050868" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:868: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:868-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-868.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer.

Several flaws were discovered in kpdf. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175105" id="175105">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050868002" comment="kdegraphics is earlier than 7:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050868004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050875" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:875: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:875-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-875.html" />
          <reference source="CVE" ref_id="CVE-2005-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4077.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols.

Stefan Esser discovered an off-by-one bug in curl. It may be possible to
execute arbitrary code on a user's machine if the user can be tricked into
executing curl with a carefully crafted URL. The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-4077 to this issue. 

All users of curl are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4077.html">CVE-2005-4077</cve>
                <bugzilla href="http://bugzilla.redhat.com/175266" id="175266">CVE-2005-4077 SA17907 cURL/libcURL URL Parsing Off-By-One Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050875002" comment="curl is earlier than 0:7.12.1-8.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050875004" comment="curl-devel is earlier than 0:7.12.1-8.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050878" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:878: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:878-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-878.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Several flaws were discovered in the way CUPS processes PDF files. An
attacker could construct a carefully crafted PDF file that could cause CUPS
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3191,
CVE-2005-3192, and CVE-2005-3193 to these issues.

All users of CUPS should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175645" id="175645">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878004" comment="cups-devel is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878006" comment="cups-libs is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878002" comment="cups is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878009" comment="cups is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050880" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:880: perl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:880-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-880.html" />
          <reference source="CVE" ref_id="CVE-2005-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3962.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

An integer overflow bug was found in Perl's format string processor.  It is
possible for an attacker to cause perl to crash or execute arbitrary code
if the attacker is able to process a malicious format string.  This issue
is only exploitable through a script which passes arbitrary untrusted
strings to the format string processor.  The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-3962 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues as well as fixes for
several bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3962.html">CVE-2005-3962</cve>
                <bugzilla href="http://bugzilla.redhat.com/170088" id="170088">bits/resource.ph has syntax errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171111" id="171111">(libperl) could not run system-config-printer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172327" id="172327">getgrnam() crashes with "Out of memory" if /etc/group contains   long lines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174683" id="174683">CVE-2005-3962 Perl integer overflow issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175104" id="175104">MakeMaker::MM_Unix doesn't honor LD_RUN_PATH requirements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175129" id="175129">missing C standard headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050880004" comment="perl-suidperl is earlier than 3:5.8.5-24.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050880002" comment="perl is earlier than 3:5.8.5-24.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050881" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:881: perl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:881-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-881.html" />
          <reference source="CVE" ref_id="CVE-2004-0976" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0976.html" />
          <reference source="CVE" ref_id="CVE-2005-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0448.html" />
          <reference source="CVE" ref_id="CVE-2005-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3962.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

An integer overflow bug was found in Perl's format string processor.  It is
possible for an attacker to cause perl to crash or execute arbitrary code
if the attacker is able to process a malicious format string.  This issue
is only exploitable through a script wich passes arbitrary untrusted
strings to the format string processor.  The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-3962 to this issue.

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module
removed directory trees.  If a local user has write permissions to a
subdirectory within the tree being removed by File::Path::rmtree, it is
possible for them to create setuid binary files.  (CVE-2005-0448)

Solar Designer discovered several temporary file bugs in various Perl
modules.  A local attacker could overwrite or create files as the user
running a Perl script that uses a vulnerable module.  (CVE-2004-0976)

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues as well as fixes for
several bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0976.html">CVE-2004-0976</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0448.html">CVE-2005-0448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3962.html">CVE-2005-3962</cve>
                <bugzilla href="http://bugzilla.redhat.com/123176" id="123176">[RFE] Need new perl rpm release that fixes threaded memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135975" id="135975">Perl's 'study' function breaks regexp matching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136325" id="136325">CVE-2004-0976 temporary file vulnerabilities in Perl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137075" id="137075">Apparent utf8 bug in Perl's join()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145215" id="145215">garbage after split()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147946" id="147946">Man::Pod does not return true</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161053" id="161053">CVE-2005-0448 perl File::Path.pm rmtree race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165078" id="165078">Broken POSIX in perl-5.8.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166732" id="166732">'split'/'index' problem for utf8</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172160" id="172160">perl bug # 22372: SIGSEGV in sv_chop()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172256" id="172256">bits/resource.ph has syntax errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172317" id="172317">(libperl) could not run system-config-printer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174717" id="174717">CVE-2005-3962 Perl integer overflow issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175135" id="175135">Cannot set undef timeout in perl 5.8.0 IO::Socket</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881006" comment="perl-CGI is earlier than 2:2.89-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881008" comment="perl-DB_File is earlier than 2:1.806-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881010" comment="perl-suidperl is earlier than 2:5.8.0-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881004" comment="perl-CPAN is earlier than 2:1.61-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881002" comment="perl is earlier than 2:5.8.0-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060015" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0015: initscripts security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0015-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0015.html" />
          <reference source="CVE" ref_id="CVE-2005-3629" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3629.html" />
    
    <description>The initscripts package contains the basic system scripts used to boot your
Red Hat system, change runlevels, and shut the system down cleanly.
Initscripts also contains the scripts that activate and deactivate most
network interfaces.

A bug was found in the way initscripts handled various environment
variables when the /sbin/service command is run. It is possible for a local
user with permissions to execute /sbin/service via sudo to execute
arbitrary commands as the 'root' user. The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-3629 to this issue.

The following issues have also been fixed in this update:

* extraneous characters were logged on bootup.

* fsck would be attempted on filesystems marked with _netdev in rc.sysinit
  before they were available.

Additionally, support for multi-core Itanium processors has been added to
redhat-support-check.

All users of initscripts should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3629.html">CVE-2005-3629</cve>
                <bugzilla href="http://bugzilla.redhat.com/169403" id="169403">Automount of the emcpower device fails if fsck is enabled for the device in /etc/fstab.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171198" id="171198">Bogus messages in system log (/var/log/messages)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060015002" comment="initscripts is earlier than 0:7.31.30.EL-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060015003" comment="initscripts is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060016" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0016: initscripts security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0016-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0016.html" />
          <reference source="CVE" ref_id="CVE-2005-3629" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3629.html" />
    
    <description>The initscripts package contains the basic system scripts used to boot
your Red Hat system, change runlevels, and shut the system down cleanly.
Initscripts also contains the scripts that activate and deactivate most
network interfaces.

A bug was found in the way initscripts handled various environment
variables when the /sbin/service command is run. It is possible for a local
user with permissions to execute /sbin/service via sudo to execute
arbitrary commands as the 'root' user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) assigned the name CVE-2005-3629 to
this issue.

The following issues have also been fixed in this update:

* extraneous characters were logged on bootup

* fsck was attempted on file systems marked with _netdev in rc.sysinit
  before they were available

* the dynamically-linked /sbin/multipath was called instead of the correct
  /sbin/multiplath.static

Additionally, this update includes support for partitioned multipath
devices and a technology preview of static IP over InifiniBand.

All users of initscripts should upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3629.html">CVE-2005-3629</cve>
                <bugzilla href="http://bugzilla.redhat.com/108827" id="108827">RHEL4:  Infiniband support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168321" id="168321">rc.sysinit call dynamicly linked multipath rather than multipath.static</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171912" id="171912">Bogus messages in system log (/var/log/messages)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172804" id="172804">Automount of the emcpower device fails if fsck is enabled for the device in /etc/fstab.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174849" id="174849">CVE-2005-3629 root shell can be gained from service if ran through sudo</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060016002" comment="initscripts is earlier than 0:7.93.24.EL-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060015003" comment="initscripts is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060044" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0044: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0044-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0044.html" />
          <reference source="CVE" ref_id="CVE-2006-0225" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0225.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

An arbitrary command execution flaw was discovered in the way scp copies
files locally. It is possible for a local attacker to create a file with a
carefully crafted name that could execute arbitrary commands as the user
running scp to copy files locally. The Common Vulnerabilities and Exposures
project (cve.mitre.org) assigned the name CVE-2006-0225 to this issue. 

The following issue has also been fixed in this update:

* If the sshd service was stopped using the sshd init script while the
  main sshd daemon was not running, the init script would kill other sshd
  processes, such as the running sessions.  For example, this could happen
  when the 'service sshd stop' command was issued twice.

Additionally, this update implements auditing of user logins through the
system audit service.

All users of openssh should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0225.html">CVE-2006-0225</cve>
                <bugzilla href="http://bugzilla.redhat.com/170466" id="170466">CVE-2006-0225 local to local copy uses shell expansion twice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170468" id="170468">init script kills all running sshd's if listening server is stopped</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170568" id="170568">add audit message to sshd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060044002" comment="openssh is earlier than 0:3.9p1-8.RHEL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060044010" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060044004" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060044006" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060044008" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060045" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0045: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0045.html" />
          <reference source="CVE" ref_id="CVE-2005-2917" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2917.html" />
    
    <description>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A denial of service flaw was found in the way squid processes certain NTLM
authentication requests.  A remote attacker could send a specially crafted
NTLM authentication request which would cause the Squid server to crash. 
The Common Vulnerabilities and Exposures project assigned the name
CVE-2005-2917 to this issue.

Several bugs have also been addressed in this update:

* An error introduced in 2.5.STABLE3-6.3E.14 where Squid can crash if a
user visits a site which has a long DNS record.

* Some authentication helpers were missing needed setuid rights.

* Squid couldn't handle a reply from a HTTP server when the reply began
with the new-line character or wasn't HTTP/1.0 or HTTP/1.1 compliant.

* User-defined error pages were not kept when the squid package was upgraded.

All users of squid should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-15" />
        <updated date="2006-03-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2917.html">CVE-2005-2917</cve>
                <bugzilla href="http://bugzilla.redhat.com/127836" id="127836">Error pages should not be replaced by updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150781" id="150781">Squid doesn't handle headers split across packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163595" id="163595">Squid blocks page served by broken server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165367" id="165367">Squid dies with signal 6 and restarts and dies ...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169269" id="169269">Error in script /usr/lib/squid/wbinfo_group.pl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170397" id="170397">pam authentication fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172693" id="172693">One translated Polish language error is missing preventing squid from startup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174029" id="174029">CVE-2005-2917 Squid malformed NTLM authentication DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060045002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060052" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0052: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0052-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0052.html" />
          <reference source="CVE" ref_id="CVE-2005-2917" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2917.html" />
    
    <description>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A denial of service flaw was found in the way squid processes certain NTLM
authentication requests. It is possible for a remote attacker to crash the
Squid server by sending a specially crafted NTLM authentication request.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CVE-2005-2917 to this issue.

The following issues have also been fixed in this update: 

* An error introduced in squid-2.5.STABLE6-3.4E.12 can crash Squid when a
  user visits a site that has a bit longer DNS record.

* An error introduced in the old package prevented Squid from returning
  correct information about large file systems. The new package is compiled
  with the IDENT lookup support so that users who want to use it do not
  have to recompile it.

* Some authentication helpers needed SETUID rights but did not have them.
  If administrators wanted to use cache administrator, they had to change
  the SETUID bit manually. The updated package sets this bit so the new
  package can be updated without manual intervention from administrators.

* Squid could not handle a reply from an HTTP server when the reply began
  with the new-line character. 

* An issue was discovered when a reply from an HTTP server was not
  HTTP 1.0 or 1.1 compliant.

* The updated package keeps user-defined error pages when the package
  is updated and it adds new ones.
 
All users of squid should upgrade to this updated package, which resolves
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2006-03-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2917.html">CVE-2005-2917</cve>
                <bugzilla href="http://bugzilla.redhat.com/160704" id="160704">squid child processes exit with signal 6.. squid crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162660" id="162660">pam authentication fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168378" id="168378">CVE-2005-2917 Squid malformed NTLM authentication DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170399" id="170399">Squid blocks page served by broken server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172375" id="172375">Error pages should not be replaced by updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172392" id="172392">One translated Polish language error is missing preventing squid from startup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172697" id="172697">Squid doesn't handle headers split across packets</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060052002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060101" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0101: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0101-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0101.html" />
          <reference source="CVE" ref_id="CVE-2002-2185" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-2185.html" />
          <reference source="CVE" ref_id="CVE-2004-1190" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1190.html" />
          <reference source="CVE" ref_id="CVE-2005-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2458.html" />
          <reference source="CVE" ref_id="CVE-2005-2709" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2709.html" />
          <reference source="CVE" ref_id="CVE-2005-2800" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2800.html" />
          <reference source="CVE" ref_id="CVE-2005-3044" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3044.html" />
          <reference source="CVE" ref_id="CVE-2005-3106" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3106.html" />
          <reference source="CVE" ref_id="CVE-2005-3109" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3109.html" />
          <reference source="CVE" ref_id="CVE-2005-3276" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3276.html" />
          <reference source="CVE" ref_id="CVE-2005-3356" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3356.html" />
          <reference source="CVE" ref_id="CVE-2005-3358" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3358.html" />
          <reference source="CVE" ref_id="CVE-2005-3784" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3784.html" />
          <reference source="CVE" ref_id="CVE-2005-3806" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3806.html" />
          <reference source="CVE" ref_id="CVE-2005-3848" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3848.html" />
          <reference source="CVE" ref_id="CVE-2005-3857" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3857.html" />
          <reference source="CVE" ref_id="CVE-2005-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3858.html" />
          <reference source="CVE" ref_id="CVE-2005-4605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4605.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues
described below:

- a flaw in network IGMP processing that a allowed a remote user on the
local network to cause a denial of service (disabling of multicast reports)
if the system is running multicast applications (CVE-2002-2185, moderate)

- a flaw which allowed a local user to write to firmware on read-only
opened /dev/cdrom devices (CVE-2004-1190, moderate) 

- a flaw in gzip/zlib handling internal to the kernel that may allow a
local user to cause a denial of service (crash) (CVE-2005-2458, low) 

- a flaw in procfs handling during unloading of modules that allowed a
local user to cause a denial of service or potentially gain privileges
(CVE-2005-2709, moderate)

- a flaw in the SCSI procfs interface that allowed a local user to cause a
denial of service (crash) (CVE-2005-2800, moderate)

- a flaw in 32-bit-compat handling of the TIOCGDEV ioctl that allowed
a local user to cause a denial of service (crash) (CVE-2005-3044, important)

- a race condition when threads share memory mapping that allowed local
users to cause a denial of service (deadlock) (CVE-2005-3106, important)

- a flaw when trying to mount a non-hfsplus filesystem using hfsplus that
allowed local users to cause a denial of service (crash) (CVE-2005-3109,
moderate)

- a minor info leak with the get_thread_area() syscall that allowed
a local user to view uninitialized kernel stack data (CVE-2005-3276, low) 

- a flaw in mq_open system call that allowed a local user to cause a denial
of service (crash) (CVE-2005-3356, important)

- a flaw in set_mempolicy that allowed a local user on some 64-bit
architectures to cause a denial of service (crash) (CVE-2005-3358, important)

- a flaw in the auto-reap of child processes that allowed a local user to
cause a denial of service (crash) (CVE-2005-3784, important)

- a flaw in the IPv6 flowlabel code that allowed a local user to cause a
denial of service (crash) (CVE-2005-3806, important)

- a flaw in network ICMP processing that allowed a local user to cause
a denial of service (memory exhaustion) (CVE-2005-3848, important)

- a flaw in file lease time-out handling that allowed a local user to cause
a denial of service (log file overflow) (CVE-2005-3857, moderate) 

- a flaw in network IPv6 xfrm handling that allowed a local user to
cause a denial of service (memory exhaustion) (CVE-2005-3858, important) 

- a flaw in procfs handling that allowed a local user to read kernel memory
(CVE-2005-4605, important)

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-17" />
        <updated date="2006-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-2185.html">CVE-2002-2185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1190.html">CVE-2004-1190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2458.html">CVE-2005-2458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2709.html">CVE-2005-2709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2800.html">CVE-2005-2800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3044.html">CVE-2005-3044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3106.html">CVE-2005-3106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3109.html">CVE-2005-3109</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3276.html">CVE-2005-3276</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3356.html">CVE-2005-3356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3358.html">CVE-2005-3358</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3784.html">CVE-2005-3784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3806.html">CVE-2005-3806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3848.html">CVE-2005-3848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3857.html">CVE-2005-3857</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3858.html">CVE-2005-3858</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4605.html">CVE-2005-4605</cve>
                <bugzilla href="http://bugzilla.redhat.com/158861" id="158861">CVE-2004-1190 Continued raw access issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165679" id="165679">CVE-2005-2458 gzip/zlib flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167696" id="167696">CVE-2005-2800 SCSI proc DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168659" id="168659">CVE-2005-3044 lost fput and sockfd_put could lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168777" id="168777">CVE-2005-3276 sys_get_thread_area minor info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168924" id="168924">CVE-2005-2709 More sysctl flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169130" id="169130">CVE-2005-3356 double decrement of mqueue_mnt->mnt_count in sys_mq_open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170262" id="170262">CVE-2005-3106 exec_mmap race DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171002" id="171002">CVE-2005-3109 HFS oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174078" id="174078">[RHEL4] CVE-2005-3784 auto-reap DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174081" id="174081">CVE-2005-3806 ipv6 DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174337" id="174337">[RHEL4] CVE-2005-3857 lease printk DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174343" id="174343">CVE-2005-3858 ip6_input_finish DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174345" id="174345">CVE-2005-3848 dst_entry leak DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174807" id="174807">CVE-2002-2185 IGMP DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175683" id="175683">CVE-2005-3358 panic caused by bad args to set_mempolicy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176812" id="176812">CVE-2005-4605 Kernel memory disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101002" comment="kernel is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101006" comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101004" comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101010" comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101012" comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060101008" comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060117" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0117: vixie-cron security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0117-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0117.html" />
          <reference source="CVE" ref_id="CVE-2005-1038" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1038.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is
possible for a local attacker to execute the crontab command in such a way
that they can view the contents of another user's crontab file. The Common
Vulnerabilities and Exposures project assigned the name CVE-2005-1038 to
this issue.

This update also fixes an issue where cron jobs could start before their
scheduled time.

All users of vixie-cron should upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1038.html">CVE-2005-1038</cve>
                <bugzilla href="http://bugzilla.redhat.com/154424" id="154424">[RHEL-3] cronjobs start too early</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162022" id="162022">CVE-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178432" id="178432">prediction: vixie-cron-4.1's pam_unix session log messages will be most unpopular</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178436" id="178436">network service interruption can cause initgroups() to delay cron job execution by more than one minute</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060117002" comment="vixie-cron is earlier than 0:4.1-10.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060129" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0129: spamassassin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0129-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0129.html" />
          <reference source="CVE" ref_id="CVE-2005-3351" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3351.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug was found in SpamAssassin.  An attacker could
construct a message in such a way that would cause SpamAssassin to crash. 
If a number of these messages are sent, it could lead to a denial of
service, potentially preventing the delivery or filtering of email. The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CVE-2005-3351 to this issue.

The following issues have also been fixed in this update:

* service spamassassin restart sometimes fails
* Content Boundary "--" throws off message parser
* sa-learn: massive memory usage on large messages
* High memory usage with many newlines
* service spamassassin messages not translated
* Numerous other bug fixes that improve spam filter accuracy and safety

Users of SpamAssassin should upgrade to this updated package containing
version 3.0.5, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3351.html">CVE-2005-3351</cve>
                <bugzilla href="http://bugzilla.redhat.com/171325" id="171325">CVE-2005-3351 Upgrade to spamassassin-3.0.5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060129002" comment="spamassassin is earlier than 0:3.0.5-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060132" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0132: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 3 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0132.html" />
          <reference source="CVE" ref_id="CVE-2006-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0095.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the third regular kernel update to Red Hat Enterprise Linux 4.

New features introduced in this update include:

- Open InfiniBand (OpenIB) support

- Serial Attached SCSI support

- NFS access control lists, asynchronous I/O

- IA64 multi-core support and sgi updates 

- Large SMP CPU limits increased using the largesmp kernel: Up to 512 CPUs
  in ia64, 128 in ppc64, and 64 in AMD64 and Intel EM64T

- Improved read-ahead performance

- Common Internet File System (CIFS) update

- Error Detection and Correction (EDAC) modules

- Unisys support

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4. 

The following security bug was fixed in this update:

- dm-crypt did not clear a structure before freeing it, which could allow
local users to discover information about cryptographic keys (CVE-2006-0095)

The following device drivers have been upgraded to new versions:

cciss: 2.6.8 to 2.6.8-rh1
ipmi_devintf: 33.4 to 33.11
ipmi_msghandler: 33.4 to 33.11
ipmi_poweroff: 33.4 to 33.11
ipmi_si: 33.4 to 33.11
ipmi_watchdog: 33.4 to 33.11
mptbase: 3.02.18 to 3.02.60.01rh
e1000: 6.0.54-k2-NAPI to 6.1.16-k2-NAPI
ixgb: 1.0.95-k2-NAPI to 1.0.100-k2-NAPI
tg3: 3.27-rh to 3.43-rh
aacraid: 1.1.2-lk2 to 1.1-5[2412]
ahci: 1.01 to 1.2
ata_piix: 1.03 to 1.05
iscsi_sfnet: 4:0.1.11-1 to 4:0.1.11-2
libata: 1.11 to 1.20
qla2100: 8.01.00b5-rh2 to 8.01.02-d3
qla2200: 8.01.00b5-rh2 to 8.01.02-d3
qla2300: 8.01.00b5-rh2 to 8.01.02-d3
qla2322: 8.01.00b5-rh2 to 8.01.02-d3
qla2xxx: 8.01.00b5-rh2 to 8.01.02-d3
qla6312: 8.01.00b5-rh2 to 8.01.02-d3
sata_nv: 0.6 to 0.8
sata_promise: 1.01 to 1.03
sata_svw: 1.06 to 1.07
sata_sx4: 0.7 to 0.8
sata_vsc: 1.0 to 1.1
cifs: 1.20 to 1.34

Added drivers:

bnx2: 1.4.25
dell_rbu: 0.7
hangcheck-timer: 0.9.0
ib_mthca: 0.06
megaraid_sas: 00.00.02.00
qla2400: 8.01.02-d3
typhoon: 1.5.7

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0095.html">CVE-2006-0095</cve>
                <bugzilla href="http://bugzilla.redhat.com/108616" id="108616">RHEL4 (IPF): Support for Additional function in Intel's Monticeto processor (HW)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108827" id="108827">RHEL4:  Infiniband support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131889" id="131889">RHEL4 U2: SATA ATAPI support (including ESB2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139949" id="139949">sym driver creates voluminous /var/log/messages entries</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141699" id="141699">FEAT: RHEL 4 U3: ia64 needs hint@pause in spinloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141851" id="141851">spin loops on both ia32 and ia32e need cpu_relax</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144477" id="144477">bonding mode=6 + dhcp doesn't work correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144703" id="144703">ia32 apps that are not large file aware can access files >= 4GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145061" id="145061">SMART support in SATA driver (P1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149294" id="149294">qlogic fabric rediscovery functionality missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150893" id="150893">On few Nocona based platforms, acpi-cpufreq driver assumes the wrong CPU freq at boot time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151549" id="151549">RHEL 4 Kernel does not provide ACL support over NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152036" id="152036">Amanda hangs on backup in case of ip_conntrack_amanda is used (RHEL4)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153971" id="153971">large usb flash drive require reboot to mount more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154387" id="154387">umount fails on nfs server side when nfs client does heavy io</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155017" id="155017">Unisys' x86_64 ES7000 loses legacy devices during boot when using latest ES7000 platform code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156437" id="156437">Writing large file to 1TB ext3 volume sometimes very slow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156602" id="156602">SCTP memory consumption, additional fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156785" id="156785">Missing SHUTDOWN notification with SCTP stream socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157241" id="157241">[RHEL4-U3] PCI Hotplug - Slot powered off after enabling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157586" id="157586">ES7000 systems won't boot with large configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159869" id="159869">Diskdump fails through ipr driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160308" id="160308">USB Key stops working after upgrade to U1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160844" id="160844">dangling POSIX locks after close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161101" id="161101">Assertion failure in journal_commit_transaction() at fs/jbd/commit.c:790: "jh->b_next_transaction == ((void *)0)"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161362" id="161362">Oracle Hangs with directio and aio using NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161597" id="161597">sysfs_remove_dir() de-references NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161617" id="161617">RHEL4 Panics at smp_apic_timer_interrupt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161846" id="161846">Problem with b44: SIOCSIFFLAGS: Cannot allocate memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162094" id="162094">read() with count > 0xffffffff panics kernel at fs/direct-io.c:886</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162731" id="162731">[RHEL4] 'getpriority/setpriority'  broken with PRIO_USER, who=0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162732" id="162732">io_cancel doesn't work properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162759" id="162759">System occasionally experienced system hangs.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162814" id="162814">Assertion failure in log_do_checkpoint</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163150" id="163150">request backport of fc transport class HBA port_id for dm-multipath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163738" id="163738">Kernel PANIC - not syncing: fatal exception</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163741" id="163741">qetharp 'Operation not supported' on non-layer2 guestlan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164298" id="164298">PANIC at rpc_wake_up_status</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164547" id="164547">Bug in IPv6 address adding error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165018" id="165018">Bonding driver fails to switch to backup link</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165092" id="165092">Bugs in kernel key managment syscall interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165154" id="165154">Bad order for release_region in error exit from i810_probe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165741" id="165741">acct does not have Large File Support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165744" id="165744">2.6: /sbin/service iptables stop hangs on modprobe -r ipt_state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165959" id="165959">NFS/RPC - timestamp conversion is wrong</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166454" id="166454">rpmbuild --rebuild glibc-2.3.4-2.12.src.rpm hangs (same problem with glibc-2.3.4-2.9.src.rpm)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166524" id="166524">Erratic behaviour when system fd limit reached</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166544" id="166544">2.6.9-16.ELsmp null pointer dereference in __bounce_end_io_read on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166589" id="166589">mount/umount can cause the block device reads to fail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166880" id="166880">[RHEL4 U1] OOPS removing ahci driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167115" id="167115">[RHEL4 U1] Bonding driver does not switch to backup interface upon active interface failure under heavy UDP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167192" id="167192">NFSv3 locking misses important kernel patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167211" id="167211">RHEL4 Panic in __wake_up_common (networking)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167630" id="167630">Multicast domain membership doesn't follow bonding failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167634" id="167634">RHEL4 __copy_user breaks on unaligned src</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167645" id="167645">RHEL4 U2 performance regression running enterprise workload</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167730" id="167730">FEAT RHEL4 U3: 10GigE Neterion Driver Update (S2io)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167731" id="167731">[RHEL4] hangcheck-timer not compiled in RHEL4 on IA64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167907" id="167907">SCTP association restart problem, possible backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168090" id="168090">ipmi_poweroff driver update for Dell &lt;8G servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168262" id="168262">[RHEL4 U1][diskdump] Diskdump from OS_INIT fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168431" id="168431">autofs removes leading path components of /net mounts on timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168483" id="168483">FEAT: [RHEL4 U3] kernel dm: Statistic information about dm devices (*)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168775" id="168775">wait() and waitpid() return inconsistencies under high load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168824" id="168824">[FEAT:][RHEL 4 U3]LVM2 Snapshot support of root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169042" id="169042">[Texas Instruments] nfs bindresvport: Address already in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169149" id="169149">oops in gss_pipe_release()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169184" id="169184">ls hangs on krb5 mountd when user has not kinit-ed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169197" id="169197">NFS client oops when debugging is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170146" id="170146">CRM648268: kernel reporting init process cutime as very large negative value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170423" id="170423">Cache invalidation bug in nfs v3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170487" id="170487">Bad: kernel panic on boot (kernel-2.6.9-22.EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170546" id="170546">kernel_lock() problem through NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170656" id="170656">iSCSI connection recovery uses session address instead of portal address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170864" id="170864">device-mapper mirroring backwards compatibility issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170887" id="170887">Neterion(S2io) adapter not functional after running offline diagnostics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170985" id="170985">RHEL 4 Update 2 Incompatibility with VMware ESX 2.5.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171060" id="171060">Marvell Yukon 88E8050 ethernet interface not supported</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171112" id="171112">Kernel oops killing process with open files on a NFS3 krb5 mount after /var/lib/nfs/rpc_pipefs has been unmounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171141" id="171141">FEAT RHEL4 U3 [diskdump]: kernel - support compressing dump data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171220" id="171220">USB: khubd deadlock on error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171705" id="171705">Kernel key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171715" id="171715">nfsd: clear signals before exiting the nfsd() thread</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171765" id="171765">linux-2.6.13-key-reiserfs.patch is incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171950" id="171950">Can't reboot on IBM xSeries 236.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171985" id="171985">rhel4 u2 - Null pointer dereference in alc880_auto_fill_dac_nids</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171989" id="171989">rhel4 modules loading signing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172081" id="172081">rename(2) onto an empty directory fails on NFS file systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172214" id="172214">Large LUNS can't be seen with Hitachi Open-L SAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172393" id="172393">No analog audio with the "Intel Corporation Enterprise Southbridge High Definition Audio (rev 08)"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172487" id="172487">Difficulty with some iSCSI targets in iscsi_sfnet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172595" id="172595">netpoll can dereference a null pointer, causing a system crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172598" id="172598">[RHEL4] tuxstat SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172839" id="172839">NMI watchdog panic during cache_alloc_refill with corrupt size-128 slabcache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172892" id="172892">kernel dm: dm-ioctl memory leak on attempt to load non-existing mapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172920" id="172920">Lock at "Initializing hardware... storage network" caused by ULi HD Audio controller enabled.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172986" id="172986">autofs doesn't remount if nfs server is unreachable at expire time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173155" id="173155">kernel dm: DM_LIST_VERSIONS_CMD ioctl reponse truncated</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173156" id="173156">kernel dm: Notify userspace when a device is renamed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173157" id="173157">kernel dm-log: big endian 64-bit corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173158" id="173158">kernel dm-log: Make mirror log arch-independent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173159" id="173159">kernel dm: move bdget outside lockfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173161" id="173161">kernel dm: Make lock_fs optional.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173163" id="173163">kernel dm snapshot: Separate out metadata reading.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173164" id="173164">kernel dm snapshot: Load metadata on table creation not resumption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173166" id="173166">kernel dm snapshot: Reduce PF_MEMALLOC usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173174" id="173174">kernel dm multipath: Fix do_end_io locking.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173194" id="173194">race condition when expiring ghosted autofs mounts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173206" id="173206">kernel dm snapshot: bio_list_merge fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173304" id="173304">Fix for SystemTap bugzilla #1345 - return probe on do_execve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173354" id="173354">unable to create sgi_sn/ptc_statistics" printed to the console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173486" id="173486">Further key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173493" id="173493">Permit key management to request already running process to instantiate a key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173912" id="173912">GFS deadlock - gfs_write (do_write_direct) and gfs_setattr (do_truncate)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173981" id="173981">kernel bug at mm/prio_tree.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174427" id="174427">SCSI errors with latest qlogic driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174760" id="174760">Provide support for more than 8 logical processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174895" id="174895">System became unresponsive to local commands.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175123" id="175123">Diskdump overwrite by SATA update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175132" id="175132">Audit fails to record syscall failures when asked to via auditctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175415" id="175415">[audit][PATCH] New user space message types</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175680" id="175680">broken U3 modsyms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175687" id="175687">autofs doesn't attempt to remount failed mount points</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175728" id="175728">Kernel panic. Server hangs and is totally unresponsive until a power cycle brings it back online.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175812" id="175812">setxattr() to a file on NFS returns EIO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175988" id="175988">hang-check timer needs to be build on S390/S390x</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176825" id="176825">broken memsets in s390 drivers.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177031" id="177031">device-mapper mirror log: avoid overrun while syncing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177136" id="177136">CVE-2006-0095 dm-crypt key leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177445" id="177445">Please consider upping NR_CPUS to 16 for x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177492" id="177492">Early panic in "io_apic_get_unique_id" on 4CPU, dual-core HT enabled EM64T System</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177522" id="177522">Kernel panic while running NFS ACL test</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177527" id="177527">Add aic94xx and sas code into RHEL4 U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177561" id="177561">Largesmp kernel does not see all logical CPUs on IBM x460</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177620" id="177620">kernel device-mapper snapshot: barriers are not supported</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177634" id="177634">AIM7 File Server Performance -15% relative to U2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177719" id="177719">BIOS bug shows the wrong number of CPUs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178839" id="178839">CPU's being incorrectly numbered</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178975" id="178975">/proc/cpuinfo shows wrong value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179057" id="179057">SCSI LLDD's oops on rmmod if devices scan w/ PQ=3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179751" id="179751">lvremove panic in dm_mod:kcopyd_client_destroy while attempting to remove a snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180353" id="180353">NPTL: under xterm -e process receives SIGHUP when child thread exits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180405" id="180405">kabi violation in multi-core detection patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181574" id="181574">device-mapper mirror removal stuck on kcopyd_client_destroy (pvmove hangs)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181884" id="181884">RHEL4 U3 "noht" boot parameter sometimes disables dual core support as well as ht support</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132002" comment="kernel is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132006" comment="kernel-doc is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132004" comment="kernel-devel is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132014" comment="kernel-smp-devel is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132016" comment="kernel-hugemem is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132008" comment="kernel-largesmp is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060132012" comment="kernel-smp is earlier than 0:2.6.9-34.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060140" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0140: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0140-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0140.html" />
          <reference source="CVE" ref_id="CVE-2002-2185" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-2185.html" />
          <reference source="CVE" ref_id="CVE-2004-1057" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1057.html" />
          <reference source="CVE" ref_id="CVE-2005-2708" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2708.html" />
          <reference source="CVE" ref_id="CVE-2005-2709" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2709.html" />
          <reference source="CVE" ref_id="CVE-2005-2973" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2973.html" />
          <reference source="CVE" ref_id="CVE-2005-3044" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3044.html" />
          <reference source="CVE" ref_id="CVE-2005-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3180.html" />
          <reference source="CVE" ref_id="CVE-2005-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3275.html" />
          <reference source="CVE" ref_id="CVE-2005-3806" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3806.html" />
          <reference source="CVE" ref_id="CVE-2005-3848" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3848.html" />
          <reference source="CVE" ref_id="CVE-2005-3857" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3857.html" />
          <reference source="CVE" ref_id="CVE-2005-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3858.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues
described below:

- a flaw in network IGMP processing that a allowed a remote user on the
local network to cause a denial of service (disabling of multicast reports)
if the system is running multicast applications (CVE-2002-2185, moderate)

- a flaw in remap_page_range() with O_DIRECT writes that allowed a local
user to cause a denial of service (crash)  (CVE-2004-1057, important)

- a flaw in exec() handling on some 64-bit architectures that allowed
a local user to cause a denial of service (crash)  (CVE-2005-2708, important)

- a flaw in procfs handling during unloading of modules that allowed a
local user to cause a denial of service or potentially gain privileges 
(CVE-2005-2709, moderate)

- a flaw in IPv6 network UDP port hash table lookups that allowed a local
user to cause a denial of service (hang)  (CVE-2005-2973, important)

- a flaw in 32-bit-compat handling of the TIOCGDEV ioctl that allowed
a local user to cause a denial of service (crash)  (CVE-2005-3044, important)

- a network buffer info leak using the orinoco driver that allowed
a remote user to possibly view uninitialized data  (CVE-2005-3180, important)

- a flaw in IPv4 network TCP and UDP netfilter handling that allowed
a local user to cause a denial of service (crash)  (CVE-2005-3275, important)

- a flaw in the IPv6 flowlabel code that allowed a local user to cause a
denial of service (crash)  (CVE-2005-3806, important)

- a flaw in network ICMP processing that allowed a local user to cause
a denial of service (memory exhaustion)  (CVE-2005-3848, important)

- a flaw in file lease time-out handling that allowed a local user to cause
a denial of service (log file overflow)  (CVE-2005-3857, moderate)

- a flaw in network IPv6 xfrm handling that allowed a local user to
cause a denial of service (memory exhaustion)  (CVE-2005-3858, important)

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architecture and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-19" />
        <updated date="2006-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-2185.html">CVE-2002-2185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1057.html">CVE-2004-1057</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2708.html">CVE-2005-2708</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2709.html">CVE-2005-2709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2973.html">CVE-2005-2973</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3044.html">CVE-2005-3044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3180.html">CVE-2005-3180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3275.html">CVE-2005-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3806.html">CVE-2005-3806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3848.html">CVE-2005-3848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3857.html">CVE-2005-3857</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3858.html">CVE-2005-3858</cve>
                <bugzilla href="http://bugzilla.redhat.com/137820" id="137820">CVE-2004-1057 VM_IO refcount issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161925" id="161925">CVE-2005-2708 user code panics kernel in exec.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168661" id="168661">CVE-2005-3044 lost fput could lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168925" id="168925">CVE-2005-2709 More sysctl flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170278" id="170278">CVE-2005-3180 orinoco driver information leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170774" id="170774">CVE-2005-2973 ipv6 infinite loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171386" id="171386">CVE-2005-3275 NAT DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174082" id="174082">CVE-2005-3806 ipv6 DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174338" id="174338">CVE-2005-3857 lease printk DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174344" id="174344">CVE-2005-3858 ip6_input_finish DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174347" id="174347">CVE-2005-3848 dst_entry leak DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174808" id="174808">CVE-2002-2185 IGMP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140004" comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140002" comment="kernel is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140006" comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140014" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140016" comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140018" comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140008" comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060140012" comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060144" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0144: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 7 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2458.html" />
          <reference source="CVE" ref_id="CVE-2005-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2801.html" />
          <reference source="CVE" ref_id="CVE-2005-3276" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3276.html" />
          <reference source="CVE" ref_id="CVE-2005-4798" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4798.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the seventh regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - addition of the bnx2, dell_rbu, and megaraid_sas device drivers
  - support for multi-core, multi-threaded Intel Itanium processors
  - upgrade of the SATA subsystem to include ATAPI and SMART support
  - optional tuning via the new numa_memory_allocator, arp_announce,
      and printk_ratelimit sysctls

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement in
the reliability and scalability of Red Hat Enterprise Linux 3.

There were numerous driver updates and security fixes (elaborated below).
Other key areas affected by fixes in this update include the networking
subsystem, the VM subsystem, NPTL handling, autofs4, the USB subsystem,
CPU enumeration, and 32-bit-exec-mode handling on 64-bit architectures.

The following device drivers have been upgraded to new versions:

  aacraid -------- 1.1.5-2412
  bnx2 ----------- 1.4.30 (new)
  dell_rbu ------- 2.1 (new)
  e1000 ---------- 6.1.16-k3
  emulex --------- 7.3.3
  fusion --------- 2.06.16.02
  ipmi ----------- 35.11
  megaraid2 ------ v2.10.10.1
  megaraid_sas --- 00.00.02.00 (new)
  tg3 ------------ 3.43RH

The following security bugs were fixed in this update:

  - a flaw in gzip/zlib handling internal to the kernel that allowed
    a local user to cause a denial of service (crash)
    (CVE-2005-2458,low)

  - a flaw in ext3 EA/ACL handling of attribute sharing that allowed
    a local user to gain privileges (CVE-2005-2801, moderate)

  - a minor info leak with the get_thread_area() syscall that allowed
    a local user to view uninitialized kernel stack data
    (CVE-2005-3276, low)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2458.html">CVE-2005-2458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2801.html">CVE-2005-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3276.html">CVE-2005-3276</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4798.html">CVE-2005-4798</cve>
                <bugzilla href="http://bugzilla.redhat.com/112004" id="112004">pppd receives error "Couldn't get channel number: bad address"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112066" id="112066">RHEL3 U5:  Support for SATA features of ICH6R (for U3, AHCI only)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117067" id="117067">RHEL3 U3:  ICH6 SATA support in ACHI mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122256" id="122256">RHEL3 U6:  SATA ATAPI support (HW)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125642" id="125642">kernel's Makefile not suited for long directory paths</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128015" id="128015">RHEL3 U4: SATA AHCI (ICH6)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129265" id="129265">kernel panic when repeatedly accessing /proc/bus/usb/devices and hot-swapping usb device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130387" id="130387">Processes with Large memory requirment causes swap usage with free memory is present.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130489" id="130489">kernel kills db2 processes because of OOM error on RHEL Update2 and Update3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130712" id="130712">RHEL3 U7:  Add SMART capabilities to libata.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131295" id="131295">Hugepages configured on kernel boot line causes x86_64 kernel boot to fail with OOM.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132547" id="132547">oops when "scsi add-single-device" sent to /proc/scsi/scsi using aic79xx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134506" id="134506">[RHEL3 U3] kernel BUG at exit.c:620!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136583" id="136583">LTC18371-  [RHEL3 U4]cpu_sibling_map[] is incorrect on x445/x440</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137101" id="137101">'noht' does not work for ia32e</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137344" id="137344">Cannot disable hyperthreading on x86_64 platform</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137998" id="137998">autofs removes leading path components of /net mounts on timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138730" id="138730">LTC12369-In RHEL 3 U4 -- top command gave segmentation fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142579" id="142579">Viper: install kernel panics on DP system with 4GB all on cpu#2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144033" id="144033">[RHEL3] poll() seems to ignore large timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145596" id="145596">SMART support in SATA driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146663" id="146663">pl2303 kernel module doesn't work with 'Aten UC-232A'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147870" id="147870">O_DIRECT to sparse areas of files give incomplete writes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150559" id="150559">Can't install RHEL3 on system with Adaptec AAR 1210SA SATA controller (sata_sil - siimage problem)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152103" id="152103">RHEL3 U5:  rhgb-client shows illegal instruction and fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152650" id="152650">aacraid driver in RHEL 3 U4 em64t causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154028" id="154028">megaraid2 driver causes panic if loaded for a second time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154385" id="154385">Crash on relocated automounts with --bind</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156396" id="156396">System crash when dump or tar 64k blocksize to tape from raid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156397" id="156397">LTC13414-32-bit ping6 on 64-bit kernel not working</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156645" id="156645">[RHEL3 U5] fails to boot installer on multiple platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156987" id="156987">FEAT: RHEL3 U5: need hint@pause in ia64 spinloops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156988" id="156988">FEAT RHEL3 U7 IPF - performance improvement for the system which CPEI occur continuously.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156999" id="156999">RHEL 3 U6: Support for cache identification through 'Deterministic Cache Parameters' [cpuid(4)]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157006" id="157006">[ CRM 488904 ] driver update for Adaptec 2410SA needed (1.1.5-2361 > 1.1.5-2371 or higher)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158819" id="158819">RHEL3 does not support USBDEVFS 32-bit ioctls on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158821" id="158821">Advanced server 3 ARP timeout messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159326" id="159326">RSS limited to 1.8GB if process pinned to one CPU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159523" id="159523">[RHEL3] Does not boot on system with ACPI table crossing page boundary</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159874" id="159874">[RHEL 3 U5] adding hotplug drive causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159977" id="159977">[RHEL3] vi --- files getting deleted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160009" id="160009">agpgart will not load for kernel 2.4.21-32 on tyan S2885 motherboard with AMD-8151 agp tunnel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160337" id="160337">Keyboard "jammed" during smp runlevel 5 boot on IBM HS20-8843 BladeServer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160539" id="160539">[RHEL3] hidden bomb of kmap_atomic/kunmap_atomic bug?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161056" id="161056">CVE-2005-2801 Lost ACLs on ext3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161160" id="161160">Reproducable panic in mdadm multipathing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161188" id="161188">Sometimes data/bss can be executable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161336" id="161336">xserver issue on blade center</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161866" id="161866">Race condition accessing PCI config space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161875" id="161875">autofs doesn't remount if nfs server is unreachable at expire time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162065" id="162065">aacraid driver hangs if Adaptec 2230SLP array not optimal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162212" id="162212">st causes system hang and kernel panic when writing to tape on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162271" id="162271">Problem with b44: SIOCSIFFLAGS: Cannot allocate memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162417" id="162417">(VM) Excessive swapping when free memory is ample</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162683" id="162683">[RHEL3 and RHEL2.1] ps command core dump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162735" id="162735">LTC8356-LSB runtime testcase T.c_oflag_X failed [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163176" id="163176">Endless loop printing traceback during kernel OOPs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163184" id="163184">Explain why the SCSI inquiry is not being returned from the sd for nearly 5 minutes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163239" id="163239">[RHEL3] change_page_attr may set _PAGE_NX for kernel code pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163307" id="163307">LTC13178-panic on i5 - sys_ppc32.c 32 bit sys_recvmsg corrupting kernel data structures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163381" id="163381">RHEL3U5 x86-64 : xw9300 &amp; numa=on swaps behaviour is unexpected</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163901" id="163901">FEAT: RHEL3 U6: ia64 multi-core and multi-threading detection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163929" id="163929">[RHEL3] [x86_64/ia64] sys_time and sys_gettimeofday disagree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164206" id="164206">U5 beta encounters NMI watchdog on Celestica Quartet with 4 Opteron 875 dualcores</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164304" id="164304">[RHEL3 U5] __wtd_down_from_wakeup not in EL3 ia64 tree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164438" id="164438">LTC12403-CMVC482920:I/O errors caused by eeh error injection-drive unavailable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164580" id="164580">NFS lockd deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164795" id="164795">/usr/src/linux-2.4.21-32.EL/Documentation/networking/e100.txt contians bad info</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164828" id="164828">RHEL 3 - request to add bnx2 driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165006" id="165006">acct does not have Large File Support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165119" id="165119">FEAT RHEL3U7: Need Intel e1000 driver update for the Dell Ophir/Rimon based PCI-E NICs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165364" id="165364">SMP kernel does not honor boot parameter "noht"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165412" id="165412">[RHEL3] The system hangs when SysRq + c is pressed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165453" id="165453">Panic after ENXIO with usb-uhci</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165475" id="165475">Problem removing a USB device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165680" id="165680">CVE-2005-2458 gzip/zlib flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165825" id="165825">Inquiry (sg) command hang after a write to tape with mptscsi driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165989" id="165989">The msync(MS_SYNC) call should fail after cable pulled from scsi disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166345" id="166345">HA NFS Cluster Problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166363" id="166363">cciss disk dump hangs if module is ever unloaded/reloaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166364" id="166364">Erratic behaviour when system fd limit reached</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166578" id="166578">aacraid driver needs to be updated to support IBM ServeRAID 8i</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166583" id="166583">aacraid driver needs to be updated to support IBM ServeRAID 8i</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166600" id="166600">CRM619504: setrlimit RLIMIT_FSIZE limited to 32-bit values, even on 64-bit kernels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166669" id="166669">[RHEL3 U5] waitpid() returns unexpected ECHILD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167674" id="167674">RHEL3: need updated forcedeth.o driver?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167800" id="167800">CRM648268: kernel reporting init process cutime as very large negative value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167942" id="167942">FEAT RHEL3 U7: Need 'bnx2' driver inclusion to support Broadcom 5708C B0 NIC and 5708S BO LOM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168226" id="168226">FEAT RHEL3 U7: LSI megaraid_sas driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168293" id="168293">Potential netconsole regression in transmit path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168315" id="168315">LTC17567-Fields 'system_potential_processor' and 'partition_max_entiteled_capacity' fields are missing from lparcfg file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168358" id="168358">FEAT RHEL3 U7: ipmi driver speedup patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168359" id="168359">FEAT RHEL3 U7: ipmi_poweroff driver update for Dell &lt;8G servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168390" id="168390">Large O_DIRECT write will hang system (MPT fusion)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168392" id="168392">kill -6 of multi-threaded application takes 30 minutes to finish</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168474" id="168474">FEAT RHEL3-U7: Support for  HT1000 IDE chipset needed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168541" id="168541">RHEL3 U7: x86_64: Remove unique APIC/IO-APIC ID check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168581" id="168581">RH EL 3 U7: add support for Broadcom 5714 and 5715C NICs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168597" id="168597">FEAT RHEL3 U7: add dell_rbu driver for Dell BIOS updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168603" id="168603">FEAT RHEL3 U7: Need TG3 update to support Broadcom 5721 C1 stepping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168681" id="168681">kernel BUG at page_alloc.c:391!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168780" id="168780">CVE-2005-3276 sys_get_thread_area minor info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168795" id="168795">RHEL3U7: ipmi driver fix for PE2650</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168896" id="168896">LSI MegaRAID RHEL3 Feature - Updated SCSI driver submission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169230" id="169230">CVE-2005-4798 nfs client: handle long symlinks properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169294" id="169294">[RHEL3 U6] __copy_user/memcpy causes random kernel panic on IA-64 systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169393" id="169393">CRM# 685278 scsi scan not seeing all luns when one lun removed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169511" id="169511">[RHEL3] 'getpriority/setpriority' broken with PRIO_USER, who=0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169662" id="169662">[RHEL3 U5] Performance problem while extracting tarballs on Fujitsu Siemens Computing D1409, Adaptec S30 array, connected to an aacraid controller.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169992" id="169992">LTC18779-Lost dirty bit in kernel memory managment [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170429" id="170429">RHEL-3: 'physical id' field in /proc/cpuinfo incorrect on AMD-64 hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170440" id="170440">[RHEL3 U5] Kernel crashing, multiple panics in aacraid driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170446" id="170446">[RHEL3 U7] netdump hangs in processing of CPU stop after diskdump failed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170529" id="170529">LTC17955-82222: Support for Serverworks chipset HT2000 Ethernet Driver (BCM5700 &amp; TG3)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170561" id="170561">Broadcom 5706/5708 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170633" id="170633">System Stops responding with "queue 6 full" messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171129" id="171129">RedHat / XW9300 / system panic when logout from GNOME with USB mouse</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171377" id="171377">LTC18818-pfault interupt race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172233" id="172233">rename(2) onto an empty directory fails on NFS file systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172334" id="172334">Invalid message 'Aieee!!!  Remote IRR still set after unlock'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172664" id="172664">Updated header file with modified author permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173280" id="173280">New icache prune export</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174005" id="174005">Update Emulex lpfc driver for RHEL 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175017" id="175017">Assertion failed! idx >= ARRAY_SIZE(xfer_mode_str),libata-core.c,ata_dev_set_mode,line=1673</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175154" id="175154">[RHEL3 U6] IOs hang in __wait_on_buffer when segments > 170</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175211" id="175211">Multicast domain membership doesn't follow bonding failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175365" id="175365">LTC19816-Cannot see a concho adapter on U7 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175624" id="175624">[RHEL3 U7 PATCH] LSI PCI Express chips to operate properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175625" id="175625">[RHEL3 U7] x86-64: Can't boot with 16 logical processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175767" id="175767">Installer appears to hang when loading mptbase module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176264" id="176264">x366 NMI error logged in infinite loop - [crm#769552] Possible regression U7 beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177023" id="177023">CRM 724200: when an active USB serial port device is removed, the system panics and locks up.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177573" id="177573">autofs doesn't attempt to remount failed mount points</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177691" id="177691">negative dentry caching causes long delay when dentry becomes valid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179168" id="179168">RHEL3U7Beta-32: Booting/Installing with SATA ATAPI Optical panics</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144006" comment="kernel-source is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144002" comment="kernel is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144008" comment="kernel-doc is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144018" comment="kernel-hugemem is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144010" comment="kernel-BOOT is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144004" comment="kernel-unsupported is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060144014" comment="kernel-smp is earlier than 0:2.4.21-40.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060156" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0156: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0156-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0156.html" />
          <reference source="CVE" ref_id="CVE-2005-3313" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3313.html" />
          <reference source="CVE" ref_id="CVE-2005-3651" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3651.html" />
          <reference source="CVE" ref_id="CVE-2005-4585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4585.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Two denial of service bugs were found in Ethereal's IRC and GTP protocol
dissectors. Ethereal could crash or stop responding if it reads a malformed
IRC or GTP packet off the network. The Common Vulnerabilities and Exposures
project (cve.mitre.org) assigned the names CVE-2005-3313 and CVE-2005-4585
to these issues.

A buffer overflow bug was found in Ethereal's OSPF protocol dissector.
Ethereal could crash or execute arbitrary code if it reads a malformed OSPF
packet off the network.  (CVE-2005-3651)

Users of ethereal should upgrade to these updated packages containing
version 0.10.14, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-11" />
        <updated date="2006-01-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3313.html">CVE-2005-3313</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3651.html">CVE-2005-3651</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4585.html">CVE-2005-4585</cve>
                <bugzilla href="http://bugzilla.redhat.com/172297" id="172297">CVE-2005-3313 Ethereal IRC dissector DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176828" id="176828">CVE-2005-4585 ethereal GTP dissector could go into an infinite loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176940" id="176940">CVE-2005-3651 ethereal OSPF Protocol Dissector Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060156004" comment="ethereal-gnome is earlier than 0:0.10.14-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060156002" comment="ethereal is earlier than 0:0.10.14-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060156008" comment="ethereal-gnome is earlier than 0:0.10.14-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060156007" comment="ethereal is earlier than 0:0.10.14-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060159" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0159: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0159-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0159.html" />
          <reference source="CVE" ref_id="CVE-2005-2970" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2970.html" />
          <reference source="CVE" ref_id="CVE-2005-3352" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3352.html" />
          <reference source="CVE" ref_id="CVE-2005-3357" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3357.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A memory leak in the worker MPM could allow remote attackers to cause a
denial of service (memory consumption) via aborted connections, which
prevents the memory for the transaction pool from being reused for other
connections.  The Common Vulnerabilities and Exposures project assigned the
name CVE-2005-2970 to this issue.  This vulnerability only affects users
who are using the non-default worker MPM.

A flaw in mod_imap when using the Referer directive with image maps was
discovered.  With certain site configurations, a remote attacker could
perform a cross-site scripting attack if a victim can be forced to visit a
malicious URL using certain web browsers.  (CVE-2005-3352)

A NULL pointer dereference flaw in mod_ssl was discovered affecting server
configurations where an SSL virtual host is configured with access control
and a custom 400 error document.  A remote attacker could send a carefully
crafted request to trigger this issue which would lead to a crash.  This
crash would only be a denial of service if using the non-default worker
MPM.  (CVE-2005-3357)

Users of httpd should update to these erratum packages which contain
backported patches to correct these issues along with some additional bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-05" />
        <updated date="2006-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2970.html">CVE-2005-2970</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3352.html">CVE-2005-3352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3357.html">CVE-2005-3357</cve>
                <bugzilla href="http://bugzilla.redhat.com/170383" id="170383">mod_ssl per-directory renegotiation with request body</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171756" id="171756">CVE-2005-2970 httpd worker MPM memory consumption DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175602" id="175602">CVE-2005-3352 cross-site scripting flaw in mod_imap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175720" id="175720">CVE-2005-3357 mod_ssl crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159004" comment="httpd-devel is earlier than 0:2.0.46-56.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159006" comment="mod_ssl is earlier than 0:2.0.46-56.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159002" comment="httpd is earlier than 0:2.0.46-56.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159011" comment="httpd-manual is earlier than 0:2.0.52-22.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582012" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159014" comment="httpd-suexec is earlier than 0:2.0.52-22.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582015" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159010" comment="httpd-devel is earlier than 0:2.0.52-22.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159013" comment="mod_ssl is earlier than 0:2.0.52-22.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060159009" comment="httpd is earlier than 0:2.0.52-22.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060160" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0160: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0160.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input and creates a typesetter-independent .dvi
(DeVice Independent) file as output.

Several flaws were discovered in the teTeX PDF parsing library. An attacker
could construct a carefully crafted PDF file that could cause teTeX to
crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3191,
CVE-2005-3192, CVE-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626,
CVE-2005-3627 and CVE-2005-3628 to these issues.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-01-19" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175109" id="175109">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177127" id="177127">[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160006" comment="tetex-xdvi is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160002" comment="tetex is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160012" comment="tetex-fonts is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160014" comment="tetex-doc is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160004" comment="tetex-latex is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160008" comment="tetex-dvips is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160010" comment="tetex-afm is earlier than 0:1.0.7-67.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160019" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160017" comment="tetex is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160022" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160023" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160018" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160020" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060160021" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060163" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0163: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0163-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0163.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Chris Evans discovered several flaws in the way CUPS processes PDF files.
An attacker could construct a carefully crafted PDF file that could cause
CUPS to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3624,
CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627 to these issues.

All users of CUPS should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-11" />
        <updated date="2006-01-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
                <bugzilla href="http://bugzilla.redhat.com/176868" id="176868">CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163004" comment="cups-devel is earlier than 1:1.1.17-13.3.36" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163006" comment="cups-libs is earlier than 1:1.1.17-13.3.36" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163002" comment="cups is earlier than 1:1.1.17-13.3.36" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060163009" comment="cups is earlier than 1:1.1.22-0.rc1.9.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060164" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0164: mod_auth_pgsql security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0164.html" />
          <reference source="CVE" ref_id="CVE-2005-3656" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3656.html" />
    
    <description>The mod_auth_pgsql package is an httpd module that allows user
authentication against information stored in a PostgreSQL database.

Several format string flaws were found in the way mod_auth_pgsql logs
information.  It may be possible for a remote attacker to execute arbitrary
code as the 'apache' user if mod_auth_pgsql is used for user
authentication. The Common Vulnerabilities and Exposures project assigned
the name CVE-2005-3656 to this issue.

Please note that this issue only affects servers which have mod_auth_pgsql
installed and configured to perform user authentication against a
PostgreSQL database.

All users of mod_auth_pgsql should upgrade to these updated packages, which
contain a backported patch to resolve this issue.

This issue does not affect the mod_auth_pgsql package supplied with Red Hat
Enterprise Linux 2.1.

Red Hat would like to thank iDefense for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-05" />
        <updated date="2006-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3656.html">CVE-2005-3656</cve>
                <bugzilla href="http://bugzilla.redhat.com/177042" id="177042">CVE-2005-3656 mod_auth_pgsql format string issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060164002" comment="mod_auth_pgsql is earlier than 0:2.0.1-4.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060164003" comment="mod_auth_pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060164005" comment="mod_auth_pgsql is earlier than 0:2.0.1-7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060164003" comment="mod_auth_pgsql is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060177" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0177: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0177.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
    
    <description>gpdf is a GNOME based viewer for Portable Document Format (PDF) files.

Chris Evans discovered several flaws in the way gpdf processes PDF files.
An attacker could construct a carefully crafted PDF file that could cause
gpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3624,
CVE-2005-3625, CVE-2005-3626, and CVE-2005-3627 to these issues.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-11" />
        <updated date="2006-01-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
                <bugzilla href="http://bugzilla.redhat.com/176865" id="176865">[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060177002" comment="gpdf is earlier than 0:2.8.2-7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060178" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0178: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0178-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0178.html" />
          <reference source="CVE" ref_id="CVE-2005-4601" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4601.html" />
          <reference source="CVE" ref_id="CVE-2006-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0082.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A shell command injection flaw was found in ImageMagick's "display"
command. It is possible to execute arbitrary commands by tricking a user
into running "display" on a file with a specially crafted name. The Common
Vulnerabilities and Exposures project (cve.mitre.org) assigned the name
CVE-2005-4601 to this issue.

A format string flaw was discovered in the way ImageMagick handles
filenames. It may be possible to execute arbitrary commands by tricking a
user into running a carefully crafted ImageMagick command. (CVE-2006-0082)

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-14" />
        <updated date="2006-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4601.html">CVE-2005-4601</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0082.html">CVE-2006-0082</cve>
                <bugzilla href="http://bugzilla.redhat.com/176837" id="176837">CVE-2005-4601 ImageMagick display command shell command injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176925" id="176925">CVE-2006-0082 ImageMagick format string vulnerability.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178004" comment="ImageMagick-devel is earlier than 0:5.5.6-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178006" comment="ImageMagick-perl is earlier than 0:5.5.6-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178002" comment="ImageMagick is earlier than 0:5.5.6-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178008" comment="ImageMagick-c++ is earlier than 0:5.5.6-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178017" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178014" comment="ImageMagick-devel is earlier than 0:6.0.7.1-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178015" comment="ImageMagick-perl is earlier than 0:6.0.7.1-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178013" comment="ImageMagick is earlier than 0:6.0.7.1-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060178016" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060184" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0184: kdelibs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0184-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0184.html" />
          <reference source="CVE" ref_id="CVE-2006-0019" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0019.html" />
    
    <description>kdelibs contains libraries for the K Desktop Environment (KDE).

A heap overflow flaw was discovered affecting kjs, the JavaScript
interpreter engine used by Konqueror and other parts of KDE.  An attacker
could create a malicious web site containing carefully crafted JavaScript
code that would trigger this flaw and possibly lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project assigned the
name CVE-2006-0019 to this issue.

NOTE: this issue does not affect KDE in Red Hat Enterprise Linux 3 or 2.1.

Users of KDE should upgrade to these updated packages, which contain a
backported patch from the KDE security team correcting this issue as well
as two bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-01-19" />
        <updated date="2006-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0019.html">CVE-2006-0019</cve>
                <bugzilla href="http://bugzilla.redhat.com/165139" id="165139">kdegraphics applications crash when Open or Save dialog is opened</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177618" id="177618">CVE-2006-0019 kjs encodeuri/decodeuri heap overflow vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178072" id="178072">pwMutex destroy failure: Device or resource busy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060184002" comment="kdelibs is earlier than 6:3.3.1-3.14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060184004" comment="kdelibs-devel is earlier than 6:3.3.1-3.14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060194" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0194: gd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0194-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0194.html" />
          <reference source="CVE" ref_id="CVE-2004-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0941.html" />
    
    <description>The gd package contains a graphics library used for the dynamic creation of
images such as PNG and JPEG.

Several buffer overflow flaws were found in the way gd allocates memory. 
An attacker could create a carefully crafted image that could execute
arbitrary code if opened by a victim using a program linked against the gd
library.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
assigned the name CVE-2004-0941 to these issues.

Users of gd should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-01" />
        <updated date="2006-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0941.html">CVE-2004-0941</cve>
                <bugzilla href="http://bugzilla.redhat.com/175413" id="175413">CVE-2004-0941 additional overflows in gd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060194006" comment="gd-devel is earlier than 0:2.0.28-4.4E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638007" comment="gd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060194004" comment="gd-progs is earlier than 0:2.0.28-4.4E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638005" comment="gd-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060194002" comment="gd is earlier than 0:2.0.28-4.4E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638003" comment="gd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060195" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0195: tar security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0195-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0195.html" />
          <reference source="CVE" ref_id="CVE-2005-1918" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1918.html" />
    
    <description>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive. 

In 2002, a path traversal flaw was found in the way GNU tar extracted
archives. A malicious user could create a tar archive that could write to
arbitrary files to which the user running GNU tar has write access
(CVE-2002-0399).  Red Hat included a backported security patch to correct
this issue in Red Hat Enterprise Linux 3, and an erratum for Red Hat
Enterprise Linux 2.1 users was issued.

During internal testing, we discovered that our backported security patch
contained an incorrect optimization and therefore was not sufficient to
completely correct this vulnerability.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) assigned the name CVE-2005-1918 to this
issue.

Users of tar should upgrade to this updated package, which contains a
replacement backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-21" />
        <updated date="2006-02-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1918.html">CVE-2005-1918</cve>
                <bugzilla href="http://bugzilla.redhat.com/140589" id="140589">CVE-2005-1918 tar archive path traversal issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140598" id="140598">CVE-2005-1918 tar archive path traversal issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060195002" comment="tar is earlier than 0:1.13.25-14.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060195003" comment="tar is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060197" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0197: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0197.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An integer overflow flaw was found in Python's PCRE library that could be
triggered by a maliciously crafted regular expression. On systems that
accept arbitrary regular expressions from untrusted users, this could be
exploited to execute arbitrary code with the privileges of the application
using the library.  The Common Vulnerabilities and Exposures project
assigned the name CVE-2005-2491 to this issue.

Users of Python should upgrade to these updated packages, which contain a
backported patch that is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-09" />
        <updated date="2006-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166335" id="166335">CVE-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197004" comment="python-devel is earlier than 0:2.2.3-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197008" comment="python-docs is earlier than 0:2.2.3-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197010" comment="tkinter is earlier than 0:2.2.3-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197002" comment="python is earlier than 0:2.2.3-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197006" comment="python-tools is earlier than 0:2.2.3-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197014" comment="python-devel is earlier than 0:2.3.4-14.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197016" comment="python-docs is earlier than 0:2.3.4-14.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197017" comment="tkinter is earlier than 0:2.3.4-14.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197013" comment="python is earlier than 0:2.3.4-14.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060197015" comment="python-tools is earlier than 0:2.3.4-14.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060199" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0199: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0199-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0199.html" />
          <reference source="CVE" ref_id="CVE-2005-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4134.html" />
          <reference source="CVE" ref_id="CVE-2006-0292" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0292.html" />
          <reference source="CVE" ref_id="CVE-2006-0296" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0296.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Igor Bukanov discovered a bug in the way Mozilla's Javascript interpreter
dereferences objects. If a user visits a malicious web page, Mozilla could
crash or execute arbitrary code as the user running Mozilla. The Common
Vulnerabilities and Exposures project assigned the name CVE-2006-0292 to
this issue.

moz_bug_r_a4 discovered a bug in Mozilla's XULDocument.persist() function.
A malicious web page could inject arbitrary RDF data into a user's
localstore.rdf file, which can cause Mozilla to execute arbitrary
javascript when a user runs Mozilla.  (CVE-2006-0296)

A denial of service bug was found in the way Mozilla saves history
information. If a user visits a web page with a very long title, it is
possible Mozilla will crash or take a very long time the next time it is
run.  (CVE-2005-4134)

Note that the Red Hat Enterprise Linux 3 packages also fix a bug when
using XSLT to transform documents. Passing DOM Nodes as parameters to
functions expecting an xsl:param could cause Mozilla to throw an exception.

Users of Mozilla are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-02-02" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4134.html">CVE-2005-4134</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0292.html">CVE-2006-0292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0296.html">CVE-2006-0296</cve>
                <bugzilla href="http://bugzilla.redhat.com/179163" id="179163">CVE-2005-4134 Very long topic history.dat DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179166" id="179166">CVE-2006-0292 javascript unrooted access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179169" id="179169">CVE-2006-0296 XULDocument.persist() RDF data injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199018" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199014" comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199016" comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199010" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199002" comment="mozilla is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199020" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199006" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199004" comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199012" comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199008" comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199031" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199029" comment="mozilla-mail is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199030" comment="mozilla-chat is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199027" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199023" comment="mozilla is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199032" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199025" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199024" comment="mozilla-nspr is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199028" comment="mozilla-devel is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060199026" comment="mozilla-nss is earlier than 37:1.7.12-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060200" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0200: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0200-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0200.html" />
          <reference source="CVE" ref_id="CVE-2005-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4134.html" />
          <reference source="CVE" ref_id="CVE-2006-0292" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0292.html" />
          <reference source="CVE" ref_id="CVE-2006-0296" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0296.html" />
    
    <description>Mozilla Firefox is an open source Web browser. 

Igor Bukanov discovered a bug in the way Firefox's Javascript interpreter
derefernces objects.  If a user visits a malicious web page, Firefox could
crash or execute arbitrary code as the user running Firefox. The Common
Vulnerabilities and Exposures project assigned the name CVE-2006-0292 to
this issue.

moz_bug_r_a4 discovered a bug in Firefox's XULDocument.persist() function.
A malicious web page could inject arbitrary RDF data into a user's
localstore.rdf file, which can cause Firefox to execute arbitrary
javascript when a user runs Firefox.  (CVE-2006-0296)

A denial of service bug was found in the way Firefox saves history
information. If a user visits a web page with a very long title, it is
possible Firefox will crash or take a very long time the next time it is
run. (CVE-2005-4134)

This update also fixes a bug when using XSLT to transform documents.
Passing DOM Nodes as parameters to functions expecting an xsl:param could
cause Firefox to throw an exception. 

Users of Firefox are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-02" />
        <updated date="2006-02-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4134.html">CVE-2005-4134</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0292.html">CVE-2006-0292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0296.html">CVE-2006-0296</cve>
                <bugzilla href="http://bugzilla.redhat.com/179171" id="179171">CVE-2005-4134 Very long topic history.dat DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179173" id="179173">CVE-2006-0292 javascript unrooted access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179175" id="179175">CVE-2006-0296 XULDocument.persist() RDF data injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060200002" comment="firefox is earlier than 0:1.0.7-1.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060201" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0201: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0201-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0201.html" />
          <reference source="CVE" ref_id="CVE-2006-0301" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0301.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

A heap based buffer overflow bug was discovered in Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0301 to this issue.

Users of Xpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.

Red Hat would like to thank Dirk Mueller for reporting this issue and
providing a patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-02-13" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0301.html">CVE-2006-0301</cve>
                <bugzilla href="http://bugzilla.redhat.com/179046" id="179046">CVE-2006-0301 PDF splash handling heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060201002" comment="xpdf is earlier than 1:3.00-11.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060204" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0204: mailman security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0204-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0204.html" />
          <reference source="CVE" ref_id="CVE-2005-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3573.html" />
          <reference source="CVE" ref_id="CVE-2005-4153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4153.html" />
    
    <description>Mailman is software to help manage email discussion lists.

A flaw in handling of UTF8 character encodings was found in Mailman.  An
attacker could send a carefully crafted email message to a mailing list run
by Mailman which would cause that particular mailing list to stop working.
The Common Vulnerabilities and Exposures project assigned the name
CVE-2005-3573 to this issue.

A flaw in date handling was found in Mailman version 2.1.4 through 2.1.6. 
An attacker could send a carefully crafted email message to a mailing list
run by Mailman which would cause the Mailman server to crash.  (CVE-2005-4153).

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3573.html">CVE-2005-3573</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4153.html">CVE-2005-4153</cve>
                <bugzilla href="http://bugzilla.redhat.com/173139" id="173139">CVE-2005-3573 Mailman Denial of Service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176089" id="176089">CVE-2005-4153 Mailman DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060204002" comment="mailman is earlier than 3:2.1.5.1-25.rhel3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060204005" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060205" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0205: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0205-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0205.html" />
          <reference source="CVE" ref_id="CVE-2006-0481" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0481.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap based buffer overflow bug was found in the way libpng strips alpha
channels from a PNG image. An attacker could create a carefully crafted PNG
image file in such a way that it could cause an application linked with
libpng to crash or execute arbitrary code when the file is opened by a
victim. The Common Vulnerabilities and Exposures project has assigned the
name CVE-2006-0481 to this issue.

Please note that the vunerable libpng function is only used by TeTeX and
XEmacs on Red Hat Enterprise Linux 4.

All users of libpng are advised to update to these updated packages which
contain a backported patch that is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-13" />
        <updated date="2006-02-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0481.html">CVE-2006-0481</cve>
                <bugzilla href="http://bugzilla.redhat.com/179455" id="179455">CVE-2006-0481 libpng heap based buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060205002" comment="libpng is earlier than 2:1.2.7-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060205004" comment="libpng-devel is earlier than 2:1.2.7-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060206" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0206: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0206.html" />
          <reference source="CVE" ref_id="CVE-2006-0301" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0301.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer.

A heap based buffer overflow bug was discovered in kpdf. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0301 to this issue.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-13" />
        <updated date="2006-02-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0301.html">CVE-2006-0301</cve>
                <bugzilla href="http://bugzilla.redhat.com/179055" id="179055">CVE-2006-0301 PDF splash handling heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060206002" comment="kdegraphics is earlier than 7:3.3.1-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060206004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060207" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0207: gnutls security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0207-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0207.html" />
          <reference source="CVE" ref_id="CVE-2006-0645" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0645.html" />
    
    <description>The GNU TLS Library provides support for cryptographic algorithms and
protocols such as TLS. GNU TLS includes Libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Several flaws were found in the way libtasn1 decodes DER.  An attacker
could create a carefully crafted invalid X.509 certificate in such a way
that could trigger this flaw if parsed by an application that uses GNU TLS.
This could lead to a denial of service (application crash).  It is not
certain if this issue could be escalated to allow arbitrary code execution. 
The Common Vulnerabilities and Exposures project assigned the name
CVE-2006-0645 to this issue.

In Red Hat Enterprise Linux 4, the GNU TLS library is only used by the
Evolution client when connecting to an Exchange server or when publishing
calendar information to a WebDAV server.

Users are advised to upgrade to these updated packages, which contain a
backported patch from the GNU TLS maintainers to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-02-10" />
        <updated date="2006-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0645.html">CVE-2006-0645</cve>
                <bugzilla href="http://bugzilla.redhat.com/180903" id="180903">CVE-2006-0645 GnuTLS x509 DER DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060207004" comment="gnutls-devel is earlier than 0:1.0.20-3.2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430005" comment="gnutls-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060207002" comment="gnutls is earlier than 0:1.0.20-3.2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430003" comment="gnutls is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060232" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0232: tar security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0232-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0232.html" />
          <reference source="CVE" ref_id="CVE-2006-0300" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0300.html" />
    
    <description>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive.

Jim Meyering discovered a buffer overflow bug in the way GNU tar extracts
malformed archives. By tricking a user into extracting a malicious tar
archive, it is possible to execute arbitrary code as the user running tar.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CVE-2006-0300 to this issue.

Users of tar should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-01" />
        <updated date="2006-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0300.html">CVE-2006-0300</cve>
                <bugzilla href="http://bugzilla.redhat.com/181772" id="181772">CVE-2006-0300 GNU tar heap overlfow bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060232002" comment="tar is earlier than 0:1.14-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060195003" comment="tar is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060262" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0262: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0262-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0262.html" />
          <reference source="CVE" ref_id="CVE-2006-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0746.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a PDF file viewer.

Marcelo Ricardo Leitner discovered that a kpdf security fix, CVE-2005-3627,
was incomplete.  Red Hat issued kdegraphics packages with this incomplete
fix in RHSA-2005:868.  An attacker could construct a carefully crafted PDF
file that could cause kpdf to crash or possibly execute arbitrary code when
opened.  The Common Vulnerabilities and Exposures project assigned the name
CVE-2006-0746 to this issue.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-09" />
        <updated date="2006-03-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0746.html">CVE-2006-0746</cve>
                <bugzilla href="http://bugzilla.redhat.com/184307" id="184307">CVE-2006-0746 kpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060262002" comment="kdegraphics is earlier than 7:3.3.1-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060262004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060264" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0264: sendmail security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0264-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0264.html" />
          <reference source="CVE" ref_id="CVE-2006-0058" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0058.html" />
    
    <description>Sendmail is a Mail Transport Agent (MTA) used to send mail between machines.

A flaw in the handling of asynchronous signals was discovered in Sendmail.
A remote attacker may be able to exploit a race condition to execute
arbitrary code as root.  The Common Vulnerabilities and Exposures project
assigned the name CVE-2006-0058 to this issue.

By default on Red Hat Enterprise Linux 3 and 4, Sendmail is configured to
only accept connections from the local host.  Therefore, only users who have
configured Sendmail to listen to remote hosts would be able to be remotely
exploited by this vulnerability.

Users of Sendmail are advised to upgrade to these erratum packages, which
contain a backported patch from the Sendmail team to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-03-22" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0058.html">CVE-2006-0058</cve>
                <bugzilla href="http://bugzilla.redhat.com/184465" id="184465">CVE-2006-0058  Sendmail race condition issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264002" comment="sendmail is earlier than 0:8.12.11-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264004" comment="sendmail-doc is earlier than 0:8.12.11-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264005" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264006" comment="sendmail-devel is earlier than 0:8.12.11-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264007" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264008" comment="sendmail-cf is earlier than 0:8.12.11-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264011" comment="sendmail is earlier than 0:8.13.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264012" comment="sendmail-doc is earlier than 0:8.13.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264005" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264013" comment="sendmail-devel is earlier than 0:8.13.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264007" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060264014" comment="sendmail-cf is earlier than 0:8.13.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060266" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0266: gnupg security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0266-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0266.html" />
          <reference source="CVE" ref_id="CVE-2006-0049" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0049.html" />
          <reference source="CVE" ref_id="CVE-2006-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0455.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

Tavis Ormandy discovered a bug in the way GnuPG verifies cryptographically
signed data with detached signatures. It is possible for an attacker to
construct a cryptographically signed message which could appear to come
from a third party.  When a victim processes a GnuPG message with a
malformed detached signature, GnuPG ignores the malformed signature,
processes and outputs the signed data, and exits with status 0, just as it
would if the signature had been valid.  In this case, GnuPG's exit status
would not indicate that no signature verification had taken place. This
issue would primarily be of concern when processing GnuPG results via an
automated script. The Common Vulnerabilities and Exposures project assigned
the name CVE-2006-0455 to this issue.

Tavis Ormandy also discovered a bug in the way GnuPG verifies
cryptographically signed data with inline signatures. It is possible for an
attacker to inject unsigned data into a signed message in such a way that
when a victim processes the message to recover the data, the unsigned data
is output along with the signed data, giving the appearance of having been
signed.  This issue is mitigated in the GnuPG shipped with Red Hat
Enterprise Linux as the --ignore-crc-error option must be passed to the gpg
executable for this attack to be successful. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0049 to this issue.

Note that neither of these issues affect the way RPM or up2date verify RPM
package files, nor is RPM vulnerable to either of these issues.

All users of GnuPG are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-03-15" />
        <updated date="2006-03-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0049.html">CVE-2006-0049</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0455.html">CVE-2006-0455</cve>
                <bugzilla href="http://bugzilla.redhat.com/167392" id="167392">initial gpg run doesn't create .gnupg/secring.gpg</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179506" id="179506">RHEL3, gnupg-1.2.1-10, gpg: Creates corrupt files (probably 2GB problem)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183484" id="183484">CVE-2006-0455 gpg will quietly exit when attempting to verify a malformed message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184556" id="184556">CVE-2006-0049 Gnupg incorrect malformed message verification</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060266002" comment="gnupg is earlier than 0:1.2.1-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060266005" comment="gnupg is earlier than 0:1.2.6-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060267" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0267: ipsec-tools security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0267.html" />
          <reference source="CVE" ref_id="CVE-2005-3732" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3732.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon.  If a
victim's machine has racoon configured in a non-recommended insecure
manner, it is possible for a remote attacker to crash the racoon daemon. 
(CVE-2005-3732)

Users of ipsec-tools should upgrade to these updated packages, which contain
backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-04-25" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3732.html">CVE-2005-3732</cve>
                <bugzilla href="http://bugzilla.redhat.com/173841" id="173841">CVE-2005-3732 ipsec-tools IKE DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181605" id="181605">CVE-2005-3732 ipsec-tools IKE DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060267002" comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060267005" comment="ipsec-tools is earlier than 0:0.3.3-6.rhel4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060271" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0271: freeradius security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0271.html" />
          <reference source="CVE" ref_id="CVE-2006-1354" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1354.html" />
          <reference source="CVE" ref_id="CVE-2005-4744" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4744.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network. 

A bug was found in the way FreeRADIUS authenticates users via the MSCHAP V2
protocol. It is possible for a remote attacker to authenticate as a victim
by sending a malformed MSCHAP V2 login request to the FreeRADIUS server.
(CVE-2006-1354)

Please note that FreeRADIUS installations not using the MSCHAP V2 protocol
for authentication are not vulnerable to this issue.

A bug was also found in the way FreeRADIUS logs SQL errors from the
sql_unixodbc module. It may be possible for an attacker to cause FreeRADIUS
to crash or execute arbitrary code if they are able to manipulate the SQL
database FreeRADIUS is connecting to. (CVE-2005-4744)

Users of FreeRADIUS should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-04" />
        <updated date="2006-04-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1354.html">CVE-2006-1354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4744.html">CVE-2005-4744</cve>
                <bugzilla href="http://bugzilla.redhat.com/167676" id="167676">CVE-2005-4744 Multiple freeradius security issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186083" id="186083">CVE-2006-1354 FreeRADIUS authentication bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271004" comment="freeradius-mysql is earlier than 0:1.0.1-2.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271006" comment="freeradius-postgresql is earlier than 0:1.0.1-2.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271008" comment="freeradius-unixODBC is earlier than 0:1.0.1-2.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271002" comment="freeradius is earlier than 0:1.0.1-2.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271012" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271013" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271014" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060271011" comment="freeradius is earlier than 0:1.0.1-3.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060272" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0272: openmotif security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0272-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0272.html" />
          <reference source="CVE" ref_id="CVE-2005-3964" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3964.html" />
    
    <description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface. 

A number of buffer overflow flaws were discovered in OpenMotif's libUil
library. It is possible for an attacker to execute arbitrary code as a
victim who has been tricked into executing a program linked against
OpenMotif, which then loads a malicious User Interface Language (UIL) file.
(CVE-2005-3964)

Users of OpenMotif are advised to upgrade to these erratum packages, which
contain a backported security patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-04" />
        <updated date="2006-04-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3964.html">CVE-2005-3964</cve>
                <bugzilla href="http://bugzilla.redhat.com/174815" id="174815">CVE-2005-3964 openmotif libUil buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272004" comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272002" comment="openmotif is earlier than 0:2.2.3-5.RHEL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272006" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272009" comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272011" comment="openmotif-devel is earlier than 0:2.2.3-10.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060272010" comment="openmotif is earlier than 0:2.2.3-10.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060276" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0276: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0276-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0276.html" />
          <reference source="CVE" ref_id="CVE-2003-1303" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1303.html" />
          <reference source="CVE" ref_id="CVE-2005-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2933.html" />
          <reference source="CVE" ref_id="CVE-2005-3883" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3883.html" />
          <reference source="CVE" ref_id="CVE-2006-0208" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0208.html" />
          <reference source="CVE" ref_id="CVE-2006-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0996.html" />
          <reference source="CVE" ref_id="CVE-2006-1490" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1490.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

The phpinfo() PHP function did not properly sanitize long strings.  An
attacker could use this to perform cross-site scripting attacks against
sites that have publicly-available PHP scripts that call phpinfo(). 
(CVE-2006-0996)

The html_entity_decode() PHP function was found to not be binary safe. An
attacker could use this flaw to disclose a certain part of the memory.  In
order for this issue to be exploitable the target site would need to have a
PHP script which called the "html_entity_decode()" function with untrusted
input from the user and displayed the result.  (CVE-2006-1490)

The error handling output was found to not properly escape HTML output in
certain cases.  An attacker could use this flaw to perform cross-site
scripting attacks against sites where both display_errors and html_errors
are enabled.  (CVE-2006-0208)

An input validation error was found in the "mb_send_mail()" function.  An
attacker could use this flaw to inject arbitrary headers in a mail sent via
a script calling the "mb_send_mail()" function where the "To" parameter can
be controlled by the attacker.  (CVE-2005-3883)

A buffer overflow flaw was discovered in uw-imap, the University of
Washington's IMAP Server.  php-imap is compiled against the static c-client
libraries from imap and therefore needed to be recompiled against the fixed
version.  This issue only affected Red Hat Enterprise Linux 3.
(CVE-2005-2933).

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-25" />
        <updated date="2006-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1303.html">CVE-2003-1303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2933.html">CVE-2005-2933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3883.html">CVE-2005-3883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0208.html">CVE-2006-0208</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0996.html">CVE-2006-0996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1490.html">CVE-2006-1490</cve>
                <bugzilla href="http://bugzilla.redhat.com/163490" id="163490">PEAR::DB autoExecute function does not work when updating with WHERE clause</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174463" id="174463">CVE-2005-3883 PHP mb_send_mail() header parsing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174528" id="174528">CVE-2005-2933 imap buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178028" id="178028">CVE-2006-0208 PHP Cross Site Scripting (XSS) flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182719" id="182719">ImageCreateFromGif does not clean up its temporary file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187230" id="187230">CVE-2006-1490 PHP memory disclosure issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187510" id="187510">CVE-2006-0996 phpinfo() XSS issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276014" comment="php-odbc is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276010" comment="php-mysql is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276002" comment="php is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276012" comment="php-pgsql is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276004" comment="php-devel is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276006" comment="php-imap is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276008" comment="php-ldap is earlier than 0:4.3.2-30.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276036" comment="php-gd is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276025" comment="php-odbc is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276023" comment="php-mysql is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276017" comment="php is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276030" comment="php-xmlrpc is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276032" comment="php-mbstring is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276024" comment="php-pgsql is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276018" comment="php-devel is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276034" comment="php-ncurses is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276026" comment="php-snmp is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276021" comment="php-imap is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276019" comment="php-pear is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276028" comment="php-domxml is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060276022" comment="php-ldap is earlier than 0:4.3.9-3.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060280" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0280: dia security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0280-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0280.html" />
          <reference source="CVE" ref_id="CVE-2006-1550" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1550.html" />
    
    <description>The Dia drawing program is designed to draw various types of diagrams.

infamous41md discovered three buffer overflow bugs in Dia's xfig file
format importer. If an attacker is able to trick a Dia user into opening a
carefully crafted xfig file, it may be possible to execute arbitrary code
as the user running Dia. (CVE-2006-1550)

Users of Dia should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-05-03" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1550.html">CVE-2006-1550</cve>
                <bugzilla href="http://bugzilla.redhat.com/187401" id="187401">CVE-2006-1550 Dia multiple buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060280002" comment="dia is earlier than 1:0.94-5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060280003" comment="dia is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060283" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0283: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0283-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0283.html" />
          <reference source="CVE" ref_id="CVE-2006-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0188.html" />
          <reference source="CVE" ref_id="CVE-2006-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0195.html" />
          <reference source="CVE" ref_id="CVE-2006-0377" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0377.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

A bug was found in the way SquirrelMail presents the right frame to the
user. If a user can be tricked into opening a carefully crafted URL, it is
possible to present the user with arbitrary HTML data. (CVE-2006-0188)

A bug was found in the way SquirrelMail filters incoming HTML email. It is
possible to cause a victim's web browser to request remote content by
opening a HTML email while running a web browser that processes certain
types of invalid style sheets. Only Internet Explorer is known to process
such malformed style sheets. (CVE-2006-0195)

A bug was found in the way SquirrelMail processes a request to select an
IMAP mailbox. If a user can be tricked into opening a carefully crafted
URL, it is possible to execute arbitrary IMAP commands as the user viewing
their mail with SquirrelMail. (CVE-2006-0377)

Users of SquirrelMail are advised to upgrade to this updated package, which
contains SquirrelMail version 1.4.6 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-03" />
        <updated date="2006-05-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0188.html">CVE-2006-0188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0195.html">CVE-2006-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0377.html">CVE-2006-0377</cve>
                <bugzilla href="http://bugzilla.redhat.com/182579" id="182579">CVE-2006-0188 Possible XSS through right_frame parameter in webmail.php</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182581" id="182581">CVE-2006-0195 Possible XSS in MagicHTML (IE only)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182584" id="182584">CVE-2006-0377 IMAP injection in sqimap_mailbox_select mailbox parameter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060283002" comment="squirrelmail is earlier than 0:1.4.6-5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060283005" comment="squirrelmail is earlier than 0:1.4.6-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060298" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0298: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0298-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0298.html" />
          <reference source="CVE" ref_id="CVE-2006-0225" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0225.html" />
          <reference source="CVE" ref_id="CVE-2003-0386" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0386.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

An arbitrary command execution flaw was discovered in the way scp copies
files locally. It is possible for a local attacker to create a file with a
carefully crafted name that could execute arbitrary commands as the user
running scp to copy files locally. (CVE-2006-0225)

The SSH daemon, when restricting host access by numeric IP addresses and
with VerifyReverseMapping disabled, allows remote attackers to bypass
"from=" and "user@host" address restrictions by connecting to a host from a
system whose reverse DNS hostname contains the numeric IP address.
(CVE-2003-0386)

The following issues have also been fixed in this update:

* If the sshd service was stopped using the sshd init script while the
  main sshd daemon was not running, the init script would kill other sshd
  processes, such as the running sessions.  For example, this could happen
  when the 'service sshd stop' command was issued twice.

* When privilege separation was enabled, the last login message was printed
  only for the root user.

* The sshd daemon was sending messages to the system log from a signal
  handler when debug logging was enabled. This could cause a deadlock of
  the user's connection.

All users of openssh should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0225.html">CVE-2006-0225</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0386.html">CVE-2003-0386</cve>
                <bugzilla href="http://bugzilla.redhat.com/164661" id="164661">CVE-2003-0386 host based access bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167886" id="167886">init script kills all running sshd's if listening server is stopped</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170463" id="170463">CVE-2006-0225 local to local copy uses shell expansion twice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172564" id="172564">I can't see "Last login" message after logged via ssh</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060298002" comment="openssh is earlier than 0:3.6.1p2-33.30.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060298010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060298004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060298006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060298008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060328" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0328: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0328-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0328.html" />
          <reference source="CVE" ref_id="CVE-2006-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0748.html" />
          <reference source="CVE" ref_id="CVE-2006-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0749.html" />
          <reference source="CVE" ref_id="CVE-2006-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1724.html" />
          <reference source="CVE" ref_id="CVE-2006-1727" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1727.html" />
          <reference source="CVE" ref_id="CVE-2006-1728" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1728.html" />
          <reference source="CVE" ref_id="CVE-2006-1729" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1729.html" />
          <reference source="CVE" ref_id="CVE-2006-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1730.html" />
          <reference source="CVE" ref_id="CVE-2006-1731" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1731.html" />
          <reference source="CVE" ref_id="CVE-2006-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1732.html" />
          <reference source="CVE" ref_id="CVE-2006-1733" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1733.html" />
          <reference source="CVE" ref_id="CVE-2006-1734" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1734.html" />
          <reference source="CVE" ref_id="CVE-2006-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1735.html" />
          <reference source="CVE" ref_id="CVE-2006-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1737.html" />
          <reference source="CVE" ref_id="CVE-2006-1738" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1738.html" />
          <reference source="CVE" ref_id="CVE-2006-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1739.html" />
          <reference source="CVE" ref_id="CVE-2006-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1740.html" />
          <reference source="CVE" ref_id="CVE-2006-1741" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1741.html" />
          <reference source="CVE" ref_id="CVE-2006-1742" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1742.html" />
          <reference source="CVE" ref_id="CVE-2006-1790" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1790.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several bugs were found in the way Firefox processes malformed javascript.
A malicious web page could modify the content of a different open web page,
possibly stealing sensitive information or conducting a cross-site
scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Firefox processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-1727,
CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Firefox processes malformed web pages.
A carefully crafted malicious web page could cause the execution of
arbitrary code as the user running Firefox. (CVE-2006-0748, CVE-2006-0749,
CVE-2006-1724, CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739,
CVE-2006-1790) 

A bug was found in the way Firefox displays the secure site icon. If a
browser is configured to display the non-default secure site modal warning
dialog, it may be possible to trick a user into believing they are viewing
a secure site. (CVE-2006-1740)

A bug was found in the way Firefox allows javascript mutation events on
"input" form elements. A malicious web page could be created in such a way
that when a user submits a form, an arbitrary file could be uploaded to the
attacker. (CVE-2006-1729)

Users of Firefox are advised to upgrade to these updated packages
containing Firefox version 1.0.8 which corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-14" />
        <updated date="2006-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0748.html">CVE-2006-0748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0749.html">CVE-2006-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1724.html">CVE-2006-1724</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1727.html">CVE-2006-1727</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1728.html">CVE-2006-1728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1729.html">CVE-2006-1729</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1730.html">CVE-2006-1730</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1731.html">CVE-2006-1731</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1732.html">CVE-2006-1732</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1733.html">CVE-2006-1733</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1734.html">CVE-2006-1734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1735.html">CVE-2006-1735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1737.html">CVE-2006-1737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1738.html">CVE-2006-1738</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1739.html">CVE-2006-1739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1740.html">CVE-2006-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1741.html">CVE-2006-1741</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1742.html">CVE-2006-1742</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1790.html">CVE-2006-1790</cve>
                <bugzilla href="http://bugzilla.redhat.com/183537" id="183537">CVE-2006-0749 Firefox Tag Order Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188814" id="188814">CVE-2006-1741 Cross-site JavaScript injection using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188816" id="188816">CVE-2006-1742 JavaScript garbage-collection hazard audit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188818" id="188818">CVE-2006-1737 Crashes with evidence of memory corruption (CVE-2006-1738, CVE-2006-1739, CVE-2006-1790))</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188820" id="188820">CVE-2006-1740 Secure-site spoof (requires security warning dialog)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188822" id="188822">CVE-2006-1735 Privilege escalation via XBL.method.eval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188824" id="188824">CVE-2006-1734 Privilege escalation using a JavaScript function's cloned parent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188826" id="188826">CVE-2006-1733 Accessing XBL compilation scope via valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188828" id="188828">CVE-2006-1732 cross-site scripting through window.controllers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188830" id="188830">CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188832" id="188832">CVE-2006-1731 Cross-site scripting using .valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188834" id="188834">CVE-2006-1724 Crashes with evidence of memory corruption (1.5.0.2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188836" id="188836">CVE-2006-1730 CSS Letter-Spacing Heap Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188838" id="188838">CVE-2006-1729 File stealing by changing input type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188840" id="188840">CVE-2006-1728 Privilege escalation using crypto.generateCRMFRequest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188842" id="188842">CVE-2006-1727 Privilege escalation through Print Preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188844" id="188844">CVE-2006-0748 Table Rebuilding Code Execution Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060328002" comment="firefox is earlier than 0:1.0.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060329" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0329: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0329-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0329.html" />
          <reference source="CVE" ref_id="CVE-2006-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0748.html" />
          <reference source="CVE" ref_id="CVE-2006-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0749.html" />
          <reference source="CVE" ref_id="CVE-2006-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0884.html" />
          <reference source="CVE" ref_id="CVE-2006-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1724.html" />
          <reference source="CVE" ref_id="CVE-2006-1727" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1727.html" />
          <reference source="CVE" ref_id="CVE-2006-1728" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1728.html" />
          <reference source="CVE" ref_id="CVE-2006-1729" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1729.html" />
          <reference source="CVE" ref_id="CVE-2006-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1730.html" />
          <reference source="CVE" ref_id="CVE-2006-1731" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1731.html" />
          <reference source="CVE" ref_id="CVE-2006-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1732.html" />
          <reference source="CVE" ref_id="CVE-2006-1733" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1733.html" />
          <reference source="CVE" ref_id="CVE-2006-1734" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1734.html" />
          <reference source="CVE" ref_id="CVE-2006-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1735.html" />
          <reference source="CVE" ref_id="CVE-2006-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1737.html" />
          <reference source="CVE" ref_id="CVE-2006-1738" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1738.html" />
          <reference source="CVE" ref_id="CVE-2006-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1739.html" />
          <reference source="CVE" ref_id="CVE-2006-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1740.html" />
          <reference source="CVE" ref_id="CVE-2006-1741" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1741.html" />
          <reference source="CVE" ref_id="CVE-2006-1742" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1742.html" />
          <reference source="CVE" ref_id="CVE-2006-1790" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1790.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found in the way Mozilla processes malformed javascript.
A malicious web page could modify the content of a different open web
page, possibly stealing sensitive information or conducting a cross-site
scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Mozilla processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-1727,
CVE-2006-1728, CVE-2006-1733, CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Mozilla processes malformed web pages. 
A carefully crafted malicious web page could cause the execution of
arbitrary code as the user running Mozilla. (CVE-2006-0748, CVE-2006-0749,
CVE-2006-1730, CVE-2006-1737, CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Mozilla displays the secure site icon. If a
browser is configured to display the non-default secure site modal warning
dialog, it may be possible to trick a user into believing they are viewing
a secure site. (CVE-2006-1740)

A bug was found in the way Mozilla allows javascript mutation events on
"input" form elements. A malicious web page could be created in such a way
that when a user submits a form, an arbitrary file could be uploaded to the
attacker. (CVE-2006-1729)

A bug was found in the way Mozilla executes in-line mail forwarding. If a
user can be tricked into forwarding a maliciously crafted mail message as
in-line content, it is possible for the message to execute javascript with
the permissions of "chrome". (CVE-2006-0884)

Users of Mozilla are advised to upgrade to these updated packages
containing Mozilla version 1.7.13 which corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-18" />
        <updated date="2006-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0748.html">CVE-2006-0748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0749.html">CVE-2006-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0884.html">CVE-2006-0884</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1724.html">CVE-2006-1724</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1727.html">CVE-2006-1727</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1728.html">CVE-2006-1728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1729.html">CVE-2006-1729</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1730.html">CVE-2006-1730</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1731.html">CVE-2006-1731</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1732.html">CVE-2006-1732</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1733.html">CVE-2006-1733</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1734.html">CVE-2006-1734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1735.html">CVE-2006-1735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1737.html">CVE-2006-1737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1738.html">CVE-2006-1738</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1739.html">CVE-2006-1739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1740.html">CVE-2006-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1741.html">CVE-2006-1741</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1742.html">CVE-2006-1742</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1790.html">CVE-2006-1790</cve>
                <bugzilla href="http://bugzilla.redhat.com/188776" id="188776">CVE-2006-1741 Cross-site JavaScript injection using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188778" id="188778">CVE-2006-1742 JavaScript garbage-collection hazard audit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188780" id="188780">CVE-2006-1737 Crashes with evidence of memory corruption (CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188782" id="188782">CVE-2006-1740 Secure-site spoof (requires security warning dialog)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188784" id="188784">CVE-2006-1735 Privilege escalation via XBL.method.eval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188787" id="188787">CVE-2006-1734 Privilege escalation using a JavaScript function's cloned parent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188789" id="188789">CVE-2006-1733 Accessing XBL compilation scope via valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188791" id="188791">CVE-2006-1732 cross-site scripting through window.controllers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188793" id="188793">CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188795" id="188795">CVE-2006-1731 Cross-site scripting using .valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188799" id="188799">CVE-2006-0884 JavaScript execution in mail when forwarding in-line</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188801" id="188801">CVE-2006-1730 CSS Letter-Spacing Heap Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188803" id="188803">CVE-2006-1729 File stealing by changing input type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188805" id="188805">CVE-2006-1728 Privilege escalation using crypto.generateCRMFRequest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188807" id="188807">CVE-2006-1727 Privilege escalation through Print Preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188810" id="188810">CVE-2006-0748 Table Rebuilding Code Execution Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329018" comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329014" comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329016" comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329010" comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329002" comment="mozilla is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329020" comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329006" comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329004" comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329012" comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329008" comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329023" comment="devhelp is earlier than 0:0.9.2-2.4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329025" comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329035" comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329033" comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329034" comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329031" comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329027" comment="mozilla is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329036" comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329029" comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329028" comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329032" comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060329030" comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060330" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0330: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0330-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0330.html" />
          <reference source="CVE" ref_id="CVE-2006-0292" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0292.html" />
          <reference source="CVE" ref_id="CVE-2006-0296" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0296.html" />
          <reference source="CVE" ref_id="CVE-2006-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0748.html" />
          <reference source="CVE" ref_id="CVE-2006-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0749.html" />
          <reference source="CVE" ref_id="CVE-2006-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0884.html" />
          <reference source="CVE" ref_id="CVE-2006-1045" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1045.html" />
          <reference source="CVE" ref_id="CVE-2006-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1724.html" />
          <reference source="CVE" ref_id="CVE-2006-1727" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1727.html" />
          <reference source="CVE" ref_id="CVE-2006-1728" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1728.html" />
          <reference source="CVE" ref_id="CVE-2006-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1730.html" />
          <reference source="CVE" ref_id="CVE-2006-1731" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1731.html" />
          <reference source="CVE" ref_id="CVE-2006-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1732.html" />
          <reference source="CVE" ref_id="CVE-2006-1733" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1733.html" />
          <reference source="CVE" ref_id="CVE-2006-1734" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1734.html" />
          <reference source="CVE" ref_id="CVE-2006-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1735.html" />
          <reference source="CVE" ref_id="CVE-2006-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1737.html" />
          <reference source="CVE" ref_id="CVE-2006-1738" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1738.html" />
          <reference source="CVE" ref_id="CVE-2006-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1739.html" />
          <reference source="CVE" ref_id="CVE-2006-1741" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1741.html" />
          <reference source="CVE" ref_id="CVE-2006-1742" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1742.html" />
          <reference source="CVE" ref_id="CVE-2006-1790" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1790.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several bugs were found in the way Thunderbird processes malformed
javascript. A malicious HTML mail message could modify the content of a
different open HTML mail message, possibly stealing sensitive information
or conducting a cross-site scripting attack. Please note that JavaScript
support is disabled by default in Thunderbird. (CVE-2006-1731,
CVE-2006-1732, CVE-2006-1741)

Several bugs were found in the way Thunderbird processes certain 
javascript actions. A malicious HTML mail message could execute arbitrary 
javascript instructions with the permissions of 'chrome', allowing the 
page to steal sensitive information or install browser malware. Please 
note that JavaScript support is disabled by default in Thunderbird. 
(CVE-2006-0292, CVE-2006-0296, CVE-2006-1727, CVE-2006-1728, CVE-2006-1733,
CVE-2006-1734, CVE-2006-1735, CVE-2006-1742)

Several bugs were found in the way Thunderbird processes malformed HTML
mail messages.  A carefully crafted malicious HTML mail message could 
cause the execution of arbitrary code as the user running Thunderbird.
(CVE-2006-0748, CVE-2006-0749, CVE-2006-1724, CVE-2006-1730, CVE-2006-1737,
CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)

A bug was found in the way Thunderbird processes certain inline content 
in HTML mail messages. It may be possible for a remote attacker to send a
carefully crafted mail message to the victim, which will fetch remote
content, even if Thunderbird is configured not to fetch remote content.
(CVE-2006-1045)

A bug was found in the way Thunderbird executes in-line mail forwarding. If
a user can be tricked into forwarding a maliciously crafted mail message as
in-line content, it is possible for the message to execute javascript with
the permissions of "chrome". (CVE-2006-0884)

Users of Thunderbird are advised to upgrade to these updated packages
containing Thunderbird version 1.0.8, which is not vulnerable to these 
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-04-21" />
        <updated date="2006-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0292.html">CVE-2006-0292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0296.html">CVE-2006-0296</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0748.html">CVE-2006-0748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0749.html">CVE-2006-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0884.html">CVE-2006-0884</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1045.html">CVE-2006-1045</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1724.html">CVE-2006-1724</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1727.html">CVE-2006-1727</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1728.html">CVE-2006-1728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1730.html">CVE-2006-1730</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1731.html">CVE-2006-1731</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1732.html">CVE-2006-1732</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1733.html">CVE-2006-1733</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1734.html">CVE-2006-1734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1735.html">CVE-2006-1735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1737.html">CVE-2006-1737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1738.html">CVE-2006-1738</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1739.html">CVE-2006-1739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1741.html">CVE-2006-1741</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1742.html">CVE-2006-1742</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1790.html">CVE-2006-1790</cve>
                <bugzilla href="http://bugzilla.redhat.com/188848" id="188848">CVE-2006-1741 Cross-site JavaScript injection using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188850" id="188850">CVE-2006-1742 JavaScript garbage-collection hazard audit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188852" id="188852">CVE-2006-1737 Crashes with evidence of memory corruption (CVE-2006-1738, CVE-2006-1739, CVE-2006-1790)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188855" id="188855">CVE-2006-1735 Privilege escalation via XBL.method.eval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188857" id="188857">CVE-2006-1734 Privilege escalation using a JavaScript function's cloned parent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188859" id="188859">CVE-2006-1733 Accessing XBL compilation scope via valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188861" id="188861">CVE-2006-1732 cross-site scripting through window.controllers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188863" id="188863">CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188865" id="188865">CVE-2006-1731 Cross-site scripting using .valueOf.call()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188867" id="188867">CVE-2006-1724 Crashes with evidence of memory corruption (1.5.0.2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188869" id="188869">CVE-2006-0884 JavaScript execution in mail when forwarding in-line</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188871" id="188871">CVE-2006-1730 CSS Letter-Spacing Heap Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188873" id="188873">CVE-2006-1728 Privilege escalation using crypto.generateCRMFRequest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188875" id="188875">CVE-2006-1727 Privilege escalation through Print Preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188877" id="188877">CVE-2006-1045 Mail Multiple Information Disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188879" id="188879">CVE-2006-0748 Table Rebuilding Code Execution Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189180" id="189180">CVE-2006-0292 javascript unrooted access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189181" id="189181">CVE-2006-0296 XULDocument.persist() RDF data injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060330002" comment="thunderbird is earlier than 0:1.0.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060354" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0354: elfutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0354.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>The elfutils packages contain a number of utility programs and libraries
related to the creation and maintenance of executable code.

The elfutils packages that originally shipped with Red Hat Enterprise Linux 4
were GPL-licensed versions which lacked some functionality. Previous
updates provided fully functional versions of elfutils only under the OSL
license. This update provides a fully functional, GPL-licensed version of
elfutils. 

In the OSL-licensed elfutils versions provided in previous updates, some
tools could sometimes crash when given corrupted input files.  (CVE-2005-1704)

Also, when the eu-strip tool was used to create separate debuginfo files
from relocatable objects such as kernel modules (.ko), the resulting
debuginfo files (.ko.debug) were sometimes corrupted.  Both of these
problems are fixed in the new version.

Users of elfutils should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-08-10" />
        <updated date="2006-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/156342" id="156342">eu-strip mangles separate debuginfo with relocation sections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159888" id="159888">CVE-2005-1704 Integer overflow in libelf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186992" id="186992">Elfutils license upgrade</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060354002" comment="elfutils is earlier than 0:0.97.1-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354003" comment="elfutils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060354008" comment="elfutils-libelf-devel is earlier than 0:0.97.1-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354009" comment="elfutils-libelf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060354004" comment="elfutils-devel is earlier than 0:0.97.1-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354005" comment="elfutils-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060354006" comment="elfutils-libelf is earlier than 0:0.97.1-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354007" comment="elfutils-libelf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060368" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0368: elfutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0368-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0368.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>The elfutils packages contain a number of utility programs and libraries
related to the creation and maintenance of executable code.

The elfutils packages that originally shipped with Red Hat Enterprise Linux
3 were GPL-licensed versions which lacked some functionality. Previous
updates provided fully functional versions of elfutils only under the OSL
license. This update provides a fully functional, GPL-licensed version of
elfutils. 

In the OSL-licensed elfutils versions provided in previous updates, some
tools could sometimes crash when given corrupted input files. (CVE-2005-1704)

Also, when the eu-strip tool was used to create separate debuginfo files
from relocatable objects such as kernel modules (.ko), the resulting
debuginfo files (.ko.debug) were sometimes corrupted.  Both of these
problems are fixed in the new version.

Users of elfutils should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/159908" id="159908">CVE-2005-1704 Integer overflow in libelf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187507" id="187507">RHEL3 U8: Elfutils license upgrade</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189114" id="189114">eu-strip mangles separate debuginfo with relocation sections</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060368002" comment="elfutils is earlier than 0:0.94.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354003" comment="elfutils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060368006" comment="elfutils-libelf-devel is earlier than 0:0.94.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354009" comment="elfutils-libelf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060368004" comment="elfutils-devel is earlier than 0:0.94.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354005" comment="elfutils-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060368008" comment="elfutils-libelf is earlier than 0:0.94.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060354007" comment="elfutils-libelf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060393" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0393: ntp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0393-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0393.html" />
          <reference source="CVE" ref_id="CVE-2005-2496" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2496.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a reference time source.

The NTP daemon (ntpd), when run with the -u option and using a string to
specify the group, uses the group ID of the user instead of the group,
which causes ntpd to run with different privileges than intended.
(CVE-2005-2496)

The following issues have also been addressed in this update: 
- The init script had several problems
- The script executed on upgrade could fail
- The man page for ntpd indicated the wrong option for specifying a chroot
directory
- The ntp daemon could crash with the message "Exiting: No more memory!"
- There is a new option for syncing the hardware clock after a successful
run of ntpdate

Users of ntp should upgrade to these updated packages, which resolve these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-08-10" />
        <updated date="2006-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2496.html">CVE-2005-2496</cve>
                <bugzilla href="http://bugzilla.redhat.com/142926" id="142926">multiple problems with ntpd init.d script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149652" id="149652">CVE-2005-2496 improper group set when running ntpd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166773" id="166773">ntp %post scriptlet fails on upgrade, if ntpd is disabled.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177052" id="177052">ntpd dies with the error "Exiting: out of memory!"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187003" id="187003">ntpdate not invoked when supplying the -x option</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060393002" comment="ntp is earlier than 0:4.2.0.a.20040617-4.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060393003" comment="ntp is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060420" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0420: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0420-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0420.html" />
          <reference source="CVE" ref_id="CVE-2006-1932" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1932.html" />
          <reference source="CVE" ref_id="CVE-2006-1933" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1933.html" />
          <reference source="CVE" ref_id="CVE-2006-1934" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1934.html" />
          <reference source="CVE" ref_id="CVE-2006-1935" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1935.html" />
          <reference source="CVE" ref_id="CVE-2006-1936" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1936.html" />
          <reference source="CVE" ref_id="CVE-2006-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1937.html" />
          <reference source="CVE" ref_id="CVE-2006-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1938.html" />
          <reference source="CVE" ref_id="CVE-2006-1939" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1939.html" />
          <reference source="CVE" ref_id="CVE-2006-1940" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1940.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Several denial of service bugs were found in Ethereal's protocol
dissectors. Ethereal could crash or stop responding if it reads a malformed
packet off the network.  (CVE-2006-1932, CVE-2006-1933, CVE-2006-1937,
CVE-2006-1938, CVE-2006-1939, CVE-2006-1940)

Several buffer overflow bugs were found in Ethereal's COPS, telnet, and
ALCAP dissectors as well as Network Instruments file code and
NetXray/Windows Sniffer file code.  Ethereal could crash or execute
arbitrary code if it reads a malformed packet off the network.
(CVE-2006-1934, CVE-2006-1935, CVE-2006-1936)

Users of ethereal should upgrade to these updated packages containing
version 0.99.0, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-03" />
        <updated date="2006-05-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1932.html">CVE-2006-1932</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1933.html">CVE-2006-1933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1934.html">CVE-2006-1934</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1935.html">CVE-2006-1935</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1936.html">CVE-2006-1936</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1937.html">CVE-2006-1937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1938.html">CVE-2006-1938</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1939.html">CVE-2006-1939</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1940.html">CVE-2006-1940</cve>
                <bugzilla href="http://bugzilla.redhat.com/189906" id="189906">CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060420004" comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060420002" comment="ethereal is earlier than 0:0.99.0-EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060420008" comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060420007" comment="ethereal is earlier than 0:0.99.0-EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060425" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0425: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0425-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0425.html" />
          <reference source="CVE" ref_id="CVE-2006-2024" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2024.html" />
          <reference source="CVE" ref_id="CVE-2006-2025" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2025.html" />
          <reference source="CVE" ref_id="CVE-2006-2026" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2026.html" />
          <reference source="CVE" ref_id="CVE-2006-2120" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2120.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

An integer overflow flaw was discovered in libtiff. An attacker could
create a carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2025)

A double free flaw was discovered in libtiff. An attacker could create a
carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2026)

Several denial of service flaws were discovered in libtiff. An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to crash. (CVE-2006-2024,
CVE-2006-2120)

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-09" />
        <updated date="2006-05-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2024.html">CVE-2006-2024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2025.html">CVE-2006-2025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2026.html">CVE-2006-2026</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2120.html">CVE-2006-2120</cve>
                <bugzilla href="http://bugzilla.redhat.com/189933" id="189933">CVE-2006-2024 multiple libtiff issues (CVE-2006-2025, CVE-2006-2026)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189974" id="189974">CVE-2006-2120 libtiff DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060425002" comment="libtiff is earlier than 0:3.5.7-25.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060425004" comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060425007" comment="libtiff is earlier than 0:3.6.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060425008" comment="libtiff-devel is earlier than 0:3.6.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060427" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0427: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0427.html" />
          <reference source="CVE" ref_id="CVE-2006-1931" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1931.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming. 

A bug was found in the way Ruby creates its xmlrpc and http servers. The
servers use a non blocking socket, which enables a remote user to cause a
denial of service condition if they are able to transmit a large volume of
information from the network server. (CVE-2006-1931)

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-09" />
        <updated date="2006-05-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1931.html">CVE-2006-1931</cve>
                <bugzilla href="http://bugzilla.redhat.com/189539" id="189539">CVE-2006-1931 Ruby http/xmlrpc server DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427012" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427010" comment="irb is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427014" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427008" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427004" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427002" comment="ruby is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060427006" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060437" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0437: Updated kernel packages for Red Hat Enterprise Linux 3 Update 8 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0437-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0437.html" />
          <reference source="CVE" ref_id="CVE-2005-3055" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3055.html" />
          <reference source="CVE" ref_id="CVE-2005-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3107.html" />
          <reference source="CVE" ref_id="CVE-2006-0741" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0741.html" />
          <reference source="CVE" ref_id="CVE-2006-0742" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0742.html" />
          <reference source="CVE" ref_id="CVE-2006-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0744.html" />
          <reference source="CVE" ref_id="CVE-2006-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1056.html" />
          <reference source="CVE" ref_id="CVE-2006-1242" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1242.html" />
          <reference source="CVE" ref_id="CVE-2006-1343" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1343.html" />
          <reference source="CVE" ref_id="CVE-2006-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2444.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the eighth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - addition of the adp94xx and dcdbas device drivers
  - diskdump support on megaraid_sas, qlogic, and swap partitions
  - support for new hardware via driver and SCSI white-list updates

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement in
the reliability and scalability of Red Hat Enterprise Linux 3.

There were numerous driver updates and security fixes (elaborated below).
Other key areas affected by fixes in this update include the networking
subsystem, the NFS and autofs4 file systems, the SCSI and USB subsystems,
and architecture-specific handling affecting AMD Opteron and Intel EM64T
processors.

The following device drivers have been added or upgraded to new versions:

  adp94xx -------- 1.0.8 (new)
  bnx2 ----------- 1.4.38
  cciss ---------- 2.4.60.RH1
  dcdbas --------- 5.6.0-1 (new)
  e1000 ---------- 7.0.33-k2
  emulex --------- 7.3.6
  forcedeth ------ 0.30
  ipmi ----------- 35.13
  qlogic --------- 7.07.04b6
  tg3 ------------ 3.52RH

The following security bugs were fixed in this update:

  - a flaw in the USB devio handling of device removal that allowed a
    local user to cause a denial of service (crash)  (CVE-2005-3055,
    moderate)

  - a flaw in the exec() handling of multi-threaded tasks using ptrace()
    that allowed a local user to cause a denial of service (hang of a
    user process)  (CVE-2005-3107, low)

  - a difference in "sysretq" operation of EM64T (as opposed to Opteron)
    processors that allowed a local user to cause a denial of service
    (crash) upon return from certain system calls  (CVE-2006-0741 and
    CVE-2006-0744, important)

  - a flaw in unaligned accesses handling on Intel Itanium processors
    that allowed a local user to cause a denial of service (crash)
    (CVE-2006-0742, important)

  - an info leak on AMD-based x86 and x86_64 systems that allowed a local
    user to retrieve the floating point exception state of a process
    run by a different user  (CVE-2006-1056, important)

  - a flaw in IPv4 packet output handling that allowed a remote user to
    bypass the zero IP ID countermeasure on systems with a disabled
    firewall  (CVE-2006-1242, low)

  - a minor info leak in socket option handling in the network code
    (CVE-2006-1343, low)

  - a flaw in IPv4 netfilter handling for the unlikely use of SNMP NAT
    processing that allowed a remote user to cause a denial of service
    (crash) or potential memory corruption  (CVE-2006-2444, moderate)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3055.html">CVE-2005-3055</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3107.html">CVE-2005-3107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0741.html">CVE-2006-0741</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0742.html">CVE-2006-0742</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0744.html">CVE-2006-0744</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1056.html">CVE-2006-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1242.html">CVE-2006-1242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1343.html">CVE-2006-1343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2444.html">CVE-2006-2444</cve>
                <bugzilla href="http://bugzilla.redhat.com/97000" id="97000">i8253 count too high! resetting...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102504" id="102504">cannot reboot on Dell 6450 with RHEL 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102973" id="102973">i8253 count too high</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/103024" id="103024">"i8253 count too high! resetting.." ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119457" id="119457">panics in generic_aio_complete_rw and unmap_kvec after __iodesc_free calls generic_aio_complete_read()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127689" id="127689">Reboot fails on Dell PowerEdge 6450</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129477" id="129477">kernel panic in umount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131881" id="131881">clock_gettime() triggers audit kill from i386 binary on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132105" id="132105">autofs (automount) failover does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132994" id="132994">kernel oops when unplugging usb serial adapter using pl2303 and mct_u232</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134555" id="134555">System hangs when rebooting Dell PE6450</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134736" id="134736">kernel panic in md driver (md lacks proper locking of device lists)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142718" id="142718">[PATCH] [RHEL3] dpt_i2o modules in RHEL gets oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146789" id="146789">Implement a better solution to the dma memory allocation done in the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146954" id="146954">megaraid2 driver fails to recognize all LSI RAID adapters when there are more than 4 with >=4GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149732" id="149732">Hang with radeon driver when DRM DRI actve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152630" id="152630">timer interrupt received twice on ATI chipset motherboard, clock runs at double speed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153954" id="153954">kernel panic when removing active USB serial converter used as serial console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154680" id="154680">Kernel panic on 8GB machines under stress running e1000 diagnostics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157667" id="157667">I/O Errors when swtiching Blade USB Media Tray</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159862" id="159862">kernel oops with usbserial (minicom key pressed)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160600" id="160600">Accessing automounted directories can cause a process to hang forever</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165246" id="165246">EHCI Host driver violates USB2.0 Specification leading to device failures.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167636" id="167636">Unable to unmount a local file system exported by NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167672" id="167672">GART error during bootup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167839" id="167839">kernel crashes with an Ooops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169261" id="169261">CVE-2005-3055 async usb devio oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170261" id="170261">CVE-2005-3107 zap_threads DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171277" id="171277">MCE arg parsing broken on x86-64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174818" id="174818">[PATCH] bonding: don't drop non-VLAN traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175143" id="175143">sys_io_setup() can leak an mm reference on failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175759" id="175759">Reboot of Dell 6450 fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177451" id="177451">Kernel panic :  Unable to handle kernel paging request at virtual address    6668c79a</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177571" id="177571">[RHEL3] [RFE] forcedeth driver on xw9300 has minimal support for ethtool and mii-tool</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178119" id="178119">[RHEL3] dump_stack() isn't implemented on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178131" id="178131">syslog-only netdump still tries to dump memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178885" id="178885">bonding mode=6 + dhcp doesn't work correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179657" id="179657">Intermittently unable to mount NFS filesystem using autofs --ghost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180968" id="180968">Data corruption in ext3 FS when running hazard (corrupt inodes)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181815" id="181815">Phantom escalating load due to flawed rq->nr_uninterruptible increment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182961" id="182961">IBM x336, x260, and x460 requires acpi=noirq bootup option.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182996" id="182996">ST Tape Driver Bug!!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183881" id="183881">kernel/libc type mismatch on siginfo_t->si_band - breaks FAM on 64bit arches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185183" id="185183">Kernel BUG at pci_dma:43 encountered</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185735" id="185735">BNX2 Patch in 2.4.21-40.EL kills "Network Device Support" config menu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186058" id="186058">CVE-2006-1242 Linux zero IP ID vulnerability?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186244" id="186244">CVE-2006-1343 Small information leak in SO_ORIGINAL_DST</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186307" id="186307">RHEL3U7 fails installation using RSA(2).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186455" id="186455">Submission of a patch for non-sequential LUN mapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186901" id="186901">make menuconfig crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187548" id="187548">IPMI startup race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187911" id="187911">CVE-2006-1056 FPU Information leak on i386/x86-64 on AMD CPUs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192633" id="192633">CVE-2006-2444 SNMP NAT netfilter memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196938" id="196938">[Beta RHEL3 U8 Regression] Processes hung while allocating stack using gdb</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437010" comment="kernel-source is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437002" comment="kernel is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437012" comment="kernel-doc is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437014" comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437018" comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437004" comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060437008" comment="kernel-smp is earlier than 0:2.4.21-47.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060451" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0451: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0451.html" />
          <reference source="CVE" ref_id="CVE-2006-1526" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1526.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces such as GNOME and KDE are designed upon. 

A buffer overflow flaw in the X.org server RENDER extension was discovered.
A malicious authorized client could exploit this issue to cause a denial of
service (crash) or potentially execute arbitrary code with root privileges
on the X.org server. (CVE-2006-1526)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.

This issue does not affect Red Hat Enterprise Linux 2.1 or 3.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-04" />
        <updated date="2006-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1526.html">CVE-2006-1526</cve>
                <bugzilla href="http://bugzilla.redhat.com/189801" id="189801">CVE-2006-1526 X.Org buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451024" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451022" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451030" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451034" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451032" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451028" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060451004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.25.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060486" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0486: mailman security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0486.html" />
          <reference source="CVE" ref_id="CVE-2006-0052" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0052.html" />
    
    <description>Mailman is software to help manage email discussion lists.

A flaw was found in the way Mailman handles MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which would cause that particular mailing list
to stop working. (CVE-2006-0052)

Users of Mailman should upgrade to this updated package, which contains
backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-09" />
        <updated date="2006-06-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0052.html">CVE-2006-0052</cve>
                <bugzilla href="http://bugzilla.redhat.com/187420" id="187420">CVE-2006-0052 Mailman DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060486002" comment="mailman is earlier than 3:2.1.5.1-25.rhel3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060486005" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060493" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0493: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0493-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0493.html" />
          <reference source="CVE" ref_id="CVE-2005-2973" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2973.html" />
          <reference source="CVE" ref_id="CVE-2005-3272" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3272.html" />
          <reference source="CVE" ref_id="CVE-2005-3359" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3359.html" />
          <reference source="CVE" ref_id="CVE-2006-0555" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0555.html" />
          <reference source="CVE" ref_id="CVE-2006-0741" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0741.html" />
          <reference source="CVE" ref_id="CVE-2006-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0744.html" />
          <reference source="CVE" ref_id="CVE-2006-1522" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1522.html" />
          <reference source="CVE" ref_id="CVE-2006-1525" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1525.html" />
          <reference source="CVE" ref_id="CVE-2006-1527" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1527.html" />
          <reference source="CVE" ref_id="CVE-2006-1528" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1528.html" />
          <reference source="CVE" ref_id="CVE-2006-1855" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1855.html" />
          <reference source="CVE" ref_id="CVE-2006-1856" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1856.html" />
          <reference source="CVE" ref_id="CVE-2006-1862" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1862.html" />
          <reference source="CVE" ref_id="CVE-2006-1864" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1864.html" />
          <reference source="CVE" ref_id="CVE-2006-2271" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2271.html" />
          <reference source="CVE" ref_id="CVE-2006-2272" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2272.html" />
          <reference source="CVE" ref_id="CVE-2006-2274" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2274.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues
described below:

* a flaw in the IPv6 implementation that allowed a local user to cause a
denial of service (infinite loop and crash) (CVE-2005-2973, important)

* a flaw in the bridge implementation that allowed a remote user to
cause forwarding of spoofed packets via poisoning of the forwarding
table with already dropped frames (CVE-2005-3272, moderate)

* a flaw in the atm module that allowed a local user to cause a denial
of service (panic) via certain socket calls (CVE-2005-3359, important)

* a flaw in the NFS client implementation that allowed a local user to
cause a denial of service (panic) via O_DIRECT writes (CVE-2006-0555,
important)

* a difference in "sysretq" operation of EM64T (as opposed to Opteron)
processors that allowed a local user to cause a denial of service
(crash) upon return from certain system calls (CVE-2006-0741 and
CVE-2006-0744, important)

* a flaw in the keyring implementation that allowed a local user to
cause a denial of service (OOPS) (CVE-2006-1522, important)

* a flaw in IP routing implementation that allowed a local user to cause
a denial of service (panic) via a request for a route for a multicast IP
(CVE-2006-1525, important)

* a flaw in the SCTP-netfilter implementation that allowed a remote user
to cause a denial of service (infinite loop) (CVE-2006-1527, important)

* a flaw in the sg driver that allowed a local user to cause a denial of
service (crash) via a dio transfer to memory mapped (mmap) IO space
(CVE-2006-1528, important)

* a flaw in the threading implementation that allowed a local user to
cause a denial of service (panic) (CVE-2006-1855, important)

* two missing LSM hooks that allowed a local user to bypass the LSM by
using readv() or writev() (CVE-2006-1856, moderate)

* a flaw in the virtual memory implementation that allowed local user to
cause a denial of service (panic) by using the lsof command
(CVE-2006-1862, important)

* a directory traversal vulnerability in smbfs that allowed a local user
to escape chroot restrictions for an SMB-mounted filesystem via "..\\"
sequences (CVE-2006-1864, moderate)

* a flaw in the ECNE chunk handling of SCTP that allowed a remote user
to cause a denial of service (panic) (CVE-2006-2271, moderate)

* a flaw in the handling of COOKIE_ECHO and HEARTBEAT control chunks of
SCTP that allowed a remote user to cause a denial of service (panic)
(CVE-2006-2272, moderate)

* a flaw in the handling of DATA fragments of SCTP that allowed a remote
user to cause a denial of service (infinite recursion and crash)
(CVE-2006-2274, moderate)


All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-24" />
        <updated date="2006-05-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2973.html">CVE-2005-2973</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3272.html">CVE-2005-3272</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3359.html">CVE-2005-3359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0555.html">CVE-2006-0555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0741.html">CVE-2006-0741</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0744.html">CVE-2006-0744</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1522.html">CVE-2006-1522</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1525.html">CVE-2006-1525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1527.html">CVE-2006-1527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1528.html">CVE-2006-1528</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1855.html">CVE-2006-1855</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1856.html">CVE-2006-1856</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1862.html">CVE-2006-1862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1864.html">CVE-2006-1864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2271.html">CVE-2006-2271</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2272.html">CVE-2006-2272</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2274.html">CVE-2006-2274</cve>
                <bugzilla href="http://bugzilla.redhat.com/168791" id="168791">CVE-2006-1528 Possible local crash by dio/mmap sg driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170772" id="170772">CVE-2005-2973 ipv6 infinite loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171383" id="171383">CVE-2005-3272 bridge poisoning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175769" id="175769">CVE-2005-3359 incorrect inrement/decrement in atm module leads to panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181795" id="181795">CVE-2006-0555 NFS client panic using O_DIRECT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183489" id="183489">CVE-2006-0741 bad elf entry address (CVE-2006-0744)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187841" id="187841">CVE-2006-1855 Old thread debugging causes false BUG() in choose_new_parent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188466" id="188466">CVE-2006-1522 DoS/bug in keyring code (security/keys/)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189260" id="189260">CVE-2006-1862 The lsof command triggers a kernel oops under heavy load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189346" id="189346">CVE-2006-1525 ip_route_input() panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189435" id="189435">CVE-2006-1864 smbfs chroot issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190460" id="190460">CVE-2006-1527 netfilter/sctp: lockup in sctp_new()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191201" id="191201">CVE-2006-2271 SCTP ECNE chunk handling DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191202" id="191202">CVE-2006-2272 SCTP incoming COOKIE_ECHO and HEARTBEAT packets DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191258" id="191258">CVE-2006-2274 SCTP DATA fragments DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191524" id="191524">CVE-2006-1856 LSM missing readv/writev</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493002" comment="kernel is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493014" comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493004" comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493010" comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493016" comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493012" comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060493006" comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060498" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0498: xscreensaver security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0498-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0498.html" />
          <reference source="CVE" ref_id="CVE-2003-1294" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1294.html" />
          <reference source="CVE" ref_id="CVE-2004-2655" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2655.html" />
    
    <description>XScreenSaver is a collection of screensavers.

A keyboard focus flaw was found in the way XScreenSaver prompts the user to
enter their password to unlock the screen. XScreenSaver did not properly
ensure it had proper keyboard focus, which could leak a users password to
the program with keyboard focus. This behavior is not common, as only certain
applications exhibit this focus error. (CVE-2004-2655)

Several flaws were found in the way various XScreenSaver screensavers
create temporary files. It may be possible for a local attacker to create a
temporary file in way that could overwrite a different file to which the user
running XScreenSaver has write permissions. (CVE-2003-1294)

Users of XScreenSaver should upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-05-23" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1294.html">CVE-2003-1294</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2655.html">CVE-2004-2655</cve>
                <bugzilla href="http://bugzilla.redhat.com/182287" id="182287">CVE-2003-1294 xscreensaver temporary file flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188149" id="188149">CVE-2004-2655 xscreensaver passes password to other applications</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060498002" comment="xscreensaver is earlier than 1:4.10-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060498003" comment="xscreensaver is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060500" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0500: freetype security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0500-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0500.html" />
          <reference source="CVE" ref_id="CVE-2006-0747" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0747.html" />
          <reference source="CVE" ref_id="CVE-2006-1861" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1861.html" />
          <reference source="CVE" ref_id="CVE-2006-2661" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2661.html" />
          <reference source="CVE" ref_id="CVE-2006-3467" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3467.html" />
    
    <description>FreeType is a free, high-quality, and portable font engine.

Chris Evans discovered several integer underflow and overflow flaws in the
FreeType font engine. If a user loads a carefully crafted font file with a
program linked against FreeType, it could cause the application to crash or
execute arbitrary code as the user. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2006-0747,
CVE-2006-1861, CVE-2006-3467)

A NULL pointer dereference flaw was found in the FreeType font engine. An
application linked against FreeType can crash upon loading a malformed font
file. (CVE-2006-2661)

Users of FreeType should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-18" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0747.html">CVE-2006-0747</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1861.html">CVE-2006-1861</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2661.html">CVE-2006-2661</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3467.html">CVE-2006-3467</cve>
                <bugzilla href="http://bugzilla.redhat.com/183676" id="183676">CVE-2006-0747 Freetype integer underflow (CVE-2006-2661)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190593" id="190593">CVE-2006-1861 freetype multiple integer overflows (CVE-2006-3467)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500006" comment="freetype-utils is earlier than 0:2.1.4-4.0.rhel3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500007" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500002" comment="freetype is earlier than 0:2.1.4-4.0.rhel3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500004" comment="freetype-demos is earlier than 0:2.1.4-4.0.rhel3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500005" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500008" comment="freetype-devel is earlier than 0:2.1.4-4.0.rhel3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500009" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500014" comment="freetype-utils is earlier than 0:2.1.9-1.rhel4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500007" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500011" comment="freetype is earlier than 0:2.1.9-1.rhel4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500012" comment="freetype-demos is earlier than 0:2.1.9-1.rhel4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500005" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060500013" comment="freetype-devel is earlier than 0:2.1.9-1.rhel4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060500009" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060515" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0515: sendmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0515-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0515.html" />
          <reference source="CVE" ref_id="CVE-2006-1173" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1173.html" />
    
    <description>Sendmail is a Mail Transport Agent (MTA) used to send mail between machines.

A flaw in the handling of multi-part MIME messages was discovered in
Sendmail.  A remote attacker could create a carefully crafted message that
could crash the sendmail process during delivery (CVE-2006-1173).  By
default on Red Hat Enterprise Linux, Sendmail is configured to only accept
connections from the local host. Therefore, only users who have configured
Sendmail to listen to remote hosts would be remotely vulnerable to this issue.

Users of Sendmail are advised to upgrade to these erratum packages, which
contain a backported patch from the Sendmail team to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-06-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1173.html">CVE-2006-1173</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515002" comment="sendmail is earlier than 0:8.12.11-4.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515008" comment="sendmail-doc is earlier than 0:8.12.11-4.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264005" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515004" comment="sendmail-devel is earlier than 0:8.12.11-4.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264007" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515006" comment="sendmail-cf is earlier than 0:8.12.11-4.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515011" comment="sendmail is earlier than 0:8.13.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515013" comment="sendmail-doc is earlier than 0:8.13.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264005" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515014" comment="sendmail-devel is earlier than 0:8.13.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264007" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060515012" comment="sendmail-cf is earlier than 0:8.13.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060264009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060525" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0525: quagga security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0525-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0525.html" />
          <reference source="CVE" ref_id="CVE-2006-2223" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2223.html" />
          <reference source="CVE" ref_id="CVE-2006-2224" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2224.html" />
          <reference source="CVE" ref_id="CVE-2006-2276" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2276.html" />
    
    <description>Quagga manages the TCP/IP based routing protocol. It takes a multi-server
and multi-thread approach to resolve the current complexity of the Internet.

An information disclosure flaw was found in the way Quagga interprets RIP
REQUEST packets. RIPd in Quagga will respond to RIP REQUEST packets for RIP
versions that have been disabled or that have authentication enabled,
allowing a remote attacker to acquire information about the local network.
(CVE-2006-2223)

A route injection flaw was found in the way Quagga interprets RIPv1
RESPONSE packets when RIPv2 authentication is enabled. It is possible for a
remote attacker to inject arbitrary route information into the RIPd routing
tables. This issue does not affect Quagga configurations where only RIPv2
is specified. (CVE-2006-2224)

A denial of service flaw was found in Quagga's telnet interface. If an
attacker is able to connect to the Quagga telnet interface, it is possible
to cause Quagga to consume vast quantities of CPU resources by issuing a
malformed 'sh' command. (CVE-2006-2276)

Users of Quagga should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-01" />
        <updated date="2006-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2223.html">CVE-2006-2223</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2224.html">CVE-2006-2224</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2276.html">CVE-2006-2276</cve>
                <bugzilla href="http://bugzilla.redhat.com/191080" id="191080">CVE-2006-2223 Quagga RIPd information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191084" id="191084">CVE-2006-2224 Quagga RIPd route injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191376" id="191376">CVE-2006-2276 quagga locks with command sh ip bgp</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525006" comment="quagga-devel is earlier than 0:0.96.2-11.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315007" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525004" comment="quagga-contrib is earlier than 0:0.96.2-11.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315005" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525002" comment="quagga is earlier than 0:0.96.2-11.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315003" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525010" comment="quagga-devel is earlier than 0:0.98.3-2.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315007" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525011" comment="quagga-contrib is earlier than 0:0.98.3-2.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315005" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060525009" comment="quagga is earlier than 0:0.98.3-2.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315003" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060526" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0526: postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0526-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0526.html" />
          <reference source="CVE" ref_id="CVE-2006-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0591.html" />
          <reference source="CVE" ref_id="CVE-2006-2313" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2313.html" />
          <reference source="CVE" ref_id="CVE-2006-2314" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2314.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A bug was found in the way PostgreSQL's PQescapeString function escapes
strings when operating in a multibyte character encoding. It is possible
for an attacker to provide an application a carefully crafted string
containing invalidly-encoded characters, which may be improperly escaped,
allowing the attacker to inject malicious SQL. While this update fixes how
PQescapeString operates, the PostgreSQL server has also been modified to
prevent such an attack occurring through unpatched clients. 
(CVE-2006-2313, CVE-2006-2314).  More details about this issue are
available in the linked PostgreSQL technical documentation.

An integer signedness bug was found in the way PostgreSQL generated
password salts. The actual salt size is only half the size of the expected
salt, making the process of brute forcing password hashes slightly easier.
This update will not strengthen already existing passwords, but all newly
assigned passwords will have the proper salt length. (CVE-2006-0591)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 7.4.13, which corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-05-23" />
        <updated date="2006-05-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0591.html">CVE-2006-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2313.html">CVE-2006-2313</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2314.html">CVE-2006-2314</cve>
                <bugzilla href="http://bugzilla.redhat.com/180536" id="180536">CVE-2006-0591 postgresql pgcrypt minor salt generation flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192169" id="192169">CVE-2006-2313, CVE-2006-2314: PostgreSQL remote SQL injection vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192171" id="192171">CVE-2006-2313, CVE-2006-2314: PostgreSQL remote SQL injection vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526012" comment="rh-postgresql-jdbc is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526008" comment="rh-postgresql-docs is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526006" comment="rh-postgresql-contrib is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526002" comment="rh-postgresql is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526022" comment="rh-postgresql-pl is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526018" comment="rh-postgresql-devel is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526004" comment="rh-postgresql-python is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526020" comment="rh-postgresql-libs is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526016" comment="rh-postgresql-server is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526014" comment="rh-postgresql-test is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526010" comment="rh-postgresql-tcl is earlier than 0:7.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526045" comment="postgresql-jdbc is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526031" comment="postgresql-docs is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526029" comment="postgresql-devel is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526041" comment="postgresql-test is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526035" comment="postgresql-contrib is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526037" comment="postgresql-libs is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526027" comment="postgresql-tcl is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526025" comment="postgresql is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526043" comment="postgresql-server is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526039" comment="postgresql-pl is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060526033" comment="postgresql-python is earlier than 0:7.4.13-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060539" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0539: vixie-cron security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0539-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0539.html" />
          <reference source="CVE" ref_id="CVE-2006-2607" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2607.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A privilege escalation flaw was found in the way Vixie Cron runs programs;
vixie-cron does not properly verify an attempt to set the current process
user id succeeded. It was possible for a malicious local users who
exhausted certain limits to execute arbitrary commands as root via cron.
(CVE-2006-2607)

All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-12" />
        <updated date="2006-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2607.html">CVE-2006-2607</cve>
                <bugzilla href="http://bugzilla.redhat.com/193146" id="193146">CVE-2006-2607 Jobs start from root when pam_limits enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060539002" comment="vixie-cron is earlier than 4:4.1-44.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060541" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0541: dia security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0541-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0541.html" />
          <reference source="CVE" ref_id="CVE-2006-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2453.html" />
          <reference source="CVE" ref_id="CVE-2006-2480" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2480.html" />
    
    <description>The Dia drawing program is designed to draw various types of diagrams.

Several format string flaws were found in the way dia displays certain
messages. If an attacker is able to trick a Dia user into opening a
carefully crafted file, it may be possible to execute arbitrary code as the
user running Dia. (CVE-2006-2453, CVE-2006-2480)

Users of Dia should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-01" />
        <updated date="2006-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2453.html">CVE-2006-2453</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2480.html">CVE-2006-2480</cve>
                <bugzilla href="http://bugzilla.redhat.com/192698" id="192698">CVE-2006-2480 Dia format string issue (CVE-2006-2453)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060541002" comment="dia is earlier than 1:0.94-5.7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060280003" comment="dia is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060543" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0543: spamassassin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0543-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0543.html" />
          <reference source="CVE" ref_id="CVE-2006-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2447.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A flaw was found with the way the Spamassassin spamd daemon processes the
virtual pop username passed to it. If a site is running spamd with both the
--vpopmail and --paranoid flags, it is possible for a remote user with the
ability to connect to the spamd daemon to execute arbitrary commands as
the user running the spamd daemon. (CVE-2006-2447)

Note: None of the IMAP or POP servers shipped with Red Hat Enterprise Linux
4 support vpopmail delivery.  Running spamd with the --vpopmail and
--paranoid flags is uncommon and not the default startup option as shipped
with Red Hat Enterprise Linux 4.

Spamassassin, as shipped in Red Hat Enterprise Linux 4, performs RBL
lookups against visi.com to help determine if an email is spam. However,
this DNS RBL has recently disappeared, resulting in mail filtering delays
and timeouts.

Users of SpamAssassin should upgrade to these updated packages containing
version 3.0.6 and backported patches, which are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-06" />
        <updated date="2006-06-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2447.html">CVE-2006-2447</cve>
                <bugzilla href="http://bugzilla.redhat.com/178580" id="178580">/etc/sysconfig/spamassasin loses file context and timestamp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191033" id="191033">spamassassin looks up broken NS domain (visi.com)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193865" id="193865">CVE-2006-2447 spamassassin arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060543002" comment="spamassassin is earlier than 0:3.0.6-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060544" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0544: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0544-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0544.html" />
          <reference source="CVE" ref_id="CVE-2006-0903" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0903.html" />
          <reference source="CVE" ref_id="CVE-2006-1516" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1516.html" />
          <reference source="CVE" ref_id="CVE-2006-1517" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1517.html" />
          <reference source="CVE" ref_id="CVE-2006-2753" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2753.html" />
          <reference source="CVE" ref_id="CVE-2006-3081" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3081.html" />
          <reference source="CVE" ref_id="CVE-2006-4380" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4380.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was found in the way the MySQL mysql_real_escape() function escaped
strings when operating in a multibyte character encoding.  An attacker
could provide an application a carefully crafted string containing
invalidly-encoded characters which may be improperly escaped, leading to
the injection of malicious SQL commands. (CVE-2006-2753)

An information disclosure flaw was found in the way the MySQL server
processed malformed usernames. An attacker could view a small portion
of server memory by supplying an anonymous login username which was not
null terminated. (CVE-2006-1516)

An information disclosure flaw was found in the way the MySQL server
executed the COM_TABLE_DUMP command. An authenticated malicious user could
send a specially crafted packet to the MySQL server which returned
random unallocated memory. (CVE-2006-1517)

A log file obfuscation flaw was found in the way the mysql_real_query()
function creates log file entries. An attacker with the the ability to call
the mysql_real_query() function against a mysql server can obfuscate the
entry the server will write to the log file.  However, an attacker needed
to have complete control over a server in order to attempt this attack.
(CVE-2006-0903)

This update also fixes numerous non-security-related flaws, such as
intermittent authentication failures.

All users of mysql are advised to upgrade to these updated packages
containing MySQL version 4.1.20, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-09" />
        <updated date="2006-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0903.html">CVE-2006-0903</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1516.html">CVE-2006-1516</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1517.html">CVE-2006-1517</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2753.html">CVE-2006-2753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3081.html">CVE-2006-3081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4380.html">CVE-2006-4380</cve>
                <bugzilla href="http://bugzilla.redhat.com/183260" id="183260">CVE-2006-0903 Mysql log file obfuscation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183277" id="183277">Client error in mysql on updates when high concurrency</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190743" id="190743">CVE-2006-1517 Mysql information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190863" id="190863">CVE-2006-1516 mysql anonymous login information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193827" id="193827">CVE-2006-2753 MySQL improper multibyte string escaping</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060544002" comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060544006" comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060544008" comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060544004" comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060547" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0547: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0547-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0547.html" />
          <reference source="CVE" ref_id="CVE-2006-2842" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2842.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

A local file disclosure flaw was found in the way SquirrelMail loads
plugins. In SquirrelMail 1.4.6 or earlier, if register_globals is on and
magic_quotes_gpc is off, it became possible for an unauthenticated remote
user to view the contents of arbitrary local files the web server has
read-access to. This configuration is neither default nor safe, and
configuring PHP with the register_globals set on is dangerous and not
recommended.  (CVE-2006-2842) 

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-03" />
        <updated date="2006-07-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2842.html">CVE-2006-2842</cve>
                <bugzilla href="http://bugzilla.redhat.com/194283" id="194283">CVE-2006-2842 Squirrelmail file inclusion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060547002" comment="squirrelmail is earlier than 0:1.4.6-7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060547005" comment="squirrelmail is earlier than 0:1.4.6-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060548" version="503" class="patch">
      <metadata>
        <title>RHSA-2006:0548: kdebase security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0548-02" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0548.html" />
          <reference source="CVE" ref_id="CVE-2006-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2449.html" />
    
    <description>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include the KDE Display Manager (KDM).

Ludwig Nussel discovered a flaw in KDM. A malicious local KDM user could
use a symlink attack to read an arbitrary file that they would not normally
have permissions to read. (CVE-2006-2449)

Note: this issue does not affect the version of KDM as shipped with Red Hat
Enterprise Linux 2.1 or 3.

All users of KDM should upgrade to these updated packages which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-06-14" />
        <updated date="2006-06-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2449.html">CVE-2006-2449</cve>
                <bugzilla href="http://bugzilla.redhat.com/194581" id="194581">CVE-2006-2449 kdm file disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060548002" comment="kdebase is earlier than 6:3.3.1-5.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060548004" comment="kdebase-devel is earlier than 6:3.3.1-5.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060568" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0568: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0568-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0568.html" />
          <reference source="CVE" ref_id="CVE-2006-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1494.html" />
          <reference source="CVE" ref_id="CVE-2006-1990" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1990.html" />
          <reference source="CVE" ref_id="CVE-2006-3017" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3017.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A directory traversal vulnerability was found in PHP.  Local users could
bypass open_basedir restrictions allowing remote attackers to create files
in arbitrary directories via the tempnam() function.  (CVE-2006-1494)

The wordwrap() PHP function did not properly check for integer overflow in
the handling of the "break" parameter. An attacker who could control the
string passed to the "break" parameter could cause a heap overflow.
(CVE-2006-1990) 

A flaw was found in the zend_hash_del() PHP function.  For PHP scripts that
rely on the use of the unset() function, a remote attacker could force
variable initialization to be bypassed.  This would be a security issue
particularly for installations that enable the "register_globals" setting.
"register_globals" is disabled by default in Red Hat Enterprise Linux.
(CVE-2006-3017)

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-12" />
        <updated date="2006-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1494.html">CVE-2006-1494</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1990.html">CVE-2006-1990</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3017.html">CVE-2006-3017</cve>
                <bugzilla href="http://bugzilla.redhat.com/189591" id="189591">CVE-2006-1494 PHP tempname open_basedir issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190033" id="190033">CVE-2006-1990 wordwrap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196256" id="196256">CVE-2006-3017 zend_hash_del bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568012" comment="php-odbc is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568010" comment="php-mysql is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568002" comment="php is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568006" comment="php-pgsql is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568014" comment="php-devel is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568004" comment="php-imap is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568008" comment="php-ldap is earlier than 0:4.3.2-33.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568036" comment="php-odbc is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568022" comment="php-gd is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568028" comment="php-mysql is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568017" comment="php is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568024" comment="php-xmlrpc is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568031" comment="php-mbstring is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568027" comment="php-pgsql is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568026" comment="php-devel is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568037" comment="php-imap is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568034" comment="php-snmp is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568018" comment="php-ncurses is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568029" comment="php-pear is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568033" comment="php-ldap is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060568020" comment="php-domxml is earlier than 0:4.3.9-3.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060571" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0571: gnupg security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0571-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0571.html" />
          <reference source="CVE" ref_id="CVE-2006-3082" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3082.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

An integer overflow flaw was found in GnuPG.  An attacker could create a
carefully crafted message packet with a large length that could cause GnuPG
to crash or possibly overwrite memory when opened. (CVE-2006-3082)

All users of GnuPG are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-18" />
        <updated date="2006-07-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3082.html">CVE-2006-3082</cve>
                <bugzilla href="http://bugzilla.redhat.com/195945" id="195945">CVE-2006-3082 gnupg integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060571002" comment="gnupg is earlier than 0:1.2.1-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060571005" comment="gnupg is earlier than 0:1.2.6-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060573" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0573: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0573-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0573.html" />
          <reference source="CVE" ref_id="CVE-2006-2198" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2198.html" />
          <reference source="CVE" ref_id="CVE-2006-2199" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2199.html" />
          <reference source="CVE" ref_id="CVE-2006-3117" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3117.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A Sun security specialist reported an issue with the application framework.
An attacker could put macros into document locations that could cause
OpenOffice.org to execute them when the file was opened by a victim.
(CVE-2006-2198)

A bug was found in the OpenOffice.org Java virtual machine implementation.
An attacker could write a carefully crafted Java applet that can break
through the "sandbox" and have full access to system resources with the
current user privileges. (CVE-2006-2199)

A buffer overflow bug was found in the OpenOffice.org file processor. An
attacker could create a carefully crafted XML file that could cause
OpenOffice.org to write data to an arbitrary location in memory when the
file was opened by a victim. (CVE-2006-3117)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-03" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2198.html">CVE-2006-2198</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2199.html">CVE-2006-2199</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3117.html">CVE-2006-3117</cve>
                <bugzilla href="http://bugzilla.redhat.com/196679" id="196679">CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573004" comment="openoffice.org-i18n is earlier than 0:1.1.2-34.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573002" comment="openoffice.org is earlier than 0:1.1.2-34.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573006" comment="openoffice.org-libs is earlier than 0:1.1.2-34.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573013" comment="openoffice.org-i18n is earlier than 0:1.1.2-34.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573009" comment="openoffice.org is earlier than 0:1.1.2-34.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573011" comment="openoffice.org-kde is earlier than 0:1.1.2-34.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060573010" comment="openoffice.org-libs is earlier than 0:1.1.2-34.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060574" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0574: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0574-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0574.html" />
          <reference source="CVE" ref_id="CVE-2006-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2451.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

During security research, Red Hat discovered a behavioral flaw in core dump
handling.  A local user could create a program that would cause a core file
to be dumped into a directory they would not normally have permissions to
write to.  This could lead to a denial of service (disk consumption), or
allow the local user to gain root privileges.  (CVE-2006-2451)

Prior to applying this update, users can remove the ability to escalate
privileges using this flaw by configuring core files to dump to an absolute
location.  By default, core files are created in the working directory of
the faulting application, but this can be overridden by specifying an
absolute location for core files in /proc/sys/kernel/core_pattern.  To
avoid a potential denial of service, a separate partition for the core
files should be used.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-07" />
        <updated date="2006-07-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2451.html">CVE-2006-2451</cve>
                <bugzilla href="http://bugzilla.redhat.com/195902" id="195902">CVE-2006-2451 Possible privilege escalation through prctl() and suid_dumpable</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574002" comment="kernel is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574018" comment="kernel-doc is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574004" comment="kernel-devel is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574010" comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574016" comment="kernel-largesmp is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574014" comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574012" comment="kernel-hugemem is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574006" comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060574008" comment="kernel-smp is earlier than 0:2.6.9-34.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060575" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0575: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 4 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0575-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0575.html" />
          <reference source="CVE" ref_id="CVE-2005-3055" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3055.html" />
          <reference source="CVE" ref_id="CVE-2005-3623" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3623.html" />
          <reference source="CVE" ref_id="CVE-2006-0038" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0038.html" />
          <reference source="CVE" ref_id="CVE-2006-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0456.html" />
          <reference source="CVE" ref_id="CVE-2006-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0457.html" />
          <reference source="CVE" ref_id="CVE-2006-0742" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0742.html" />
          <reference source="CVE" ref_id="CVE-2006-1052" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1052.html" />
          <reference source="CVE" ref_id="CVE-2006-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1056.html" />
          <reference source="CVE" ref_id="CVE-2006-1242" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1242.html" />
          <reference source="CVE" ref_id="CVE-2006-1343" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1343.html" />
          <reference source="CVE" ref_id="CVE-2006-1857" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1857.html" />
          <reference source="CVE" ref_id="CVE-2006-2275" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2275.html" />
          <reference source="CVE" ref_id="CVE-2006-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2446.html" />
          <reference source="CVE" ref_id="CVE-2006-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2448.html" />
          <reference source="CVE" ref_id="CVE-2006-2934" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2934.html" />
    
    <description>New features introduced in this update include:

* Device Mapper mirroring support

* IDE diskdump support

* x86, AMD64 and Intel EM64T: Multi-core scheduler support enhancements

* Itanium: perfmon support for Montecito

* much improved support for IBM x460

* AMD PowerNow! patches to support Opteron Rev G

* Vmalloc support > 64MB

The following device drivers have been upgraded to new versions:

ipmi: 33.11 to 33.13
ib_mthca: 0.06 to 0.08
bnx2: 1.4.30 to 1.4.38
bonding: 2.6.1 to 2.6.3
e100: 3.4.8-k2-NAPI to 3.5.10-k2-NAPI
e1000: 6.1.16-k3-NAPI to 7.0.33-k2-NAPI
sky2: 0.13 to 1.1
tg3: 3.43-rh to 3.52-rh
ipw2100: 1.1.0 to git-1.1.4
ipw2200: 1.0.0 to git-1.0.10
3w-9xxx: 2.26.02.001 to 2.26.04.010
ips: 7.10.18 to 7.12.02
iscsi_sfnet: 4:0.1.11-2 to 4:0.1.11-3
lpfc: 0:8.0.16.18 to 0:8.0.16.27
megaraid_sas: 00.00.02.00 to 00.00.02.03-RH1
qla2xxx: 8.01.02-d4 to 8.01.04-d7
qla6312: 8.01.02-d4 to 8.01.04-d7
sata_promise: 1.03 to 1.04
sata_vsc: 1.1 to 1.2
ibmvscsic: 1.5.5 to 1.5.6
ipr: 2.0.11.1 to 2.0.11.2

Added drivers:

dcdbas: 5.6.0-2
sata_mv: 0.6
sata_qstor: 0.05
sata_uli: 0.5
skge: 1.1
stex: 2.9.0.13
pdc_adma: 0.03

This update includes fixes for the security issues:

* a flaw in the USB devio handling of device removal that allowed a
local user to cause a denial of service (crash) (CVE-2005-3055,
moderate)

* a flaw in the ACL handling of nfsd that allowed a remote user to
bypass ACLs for readonly mounted NFS file systems (CVE-2005-3623,
moderate)

* a flaw in the netfilter handling that allowed a local user with
CAP_NET_ADMIN rights to cause a buffer overflow (CVE-2006-0038, low)

* a flaw in the IBM S/390 and IBM zSeries strnlen_user() function that
allowed a local user to cause a denial of service (crash) or to retrieve
random kernel data (CVE-2006-0456, important)

* a flaw in the keyctl functions that allowed a local user to cause a
denial of service (crash) or to read sensitive kernel memory
(CVE-2006-0457, important)

* a flaw in unaligned accesses handling on Itanium processors that
allowed a local user to cause a denial of service (crash)
(CVE-2006-0742, important)

* a flaw in SELinux ptrace logic that allowed a local user with ptrace
permissions to change the tracer SID to a SID of another process
(CVE-2006-1052, moderate)

* an info leak on AMD-based x86 and x86_64 systems that allowed a local
user to retrieve the floating point exception state of a process run by a
different user (CVE-2006-1056, important)

* a flaw in IPv4 packet output handling that allowed a remote user to
bypass the zero IP ID countermeasure on systems with a disabled firewall
(CVE-2006-1242, low)

* a minor info leak in socket option handling in the network code
(CVE-2006-1343, low)

* a flaw in the HB-ACK chunk handling of SCTP that allowed a remote user to
cause a denial of service (crash) (CVE-2006-1857, moderate)

* a flaw in the SCTP implementation that allowed a remote user to cause a
denial of service (deadlock) (CVE-2006-2275, moderate)

* a flaw in the socket buffer handling that allowed a remote user to cause
a denial of service (panic) (CVE-2006-2446, important)

* a flaw in the signal handling access checking on PowerPC that allowed a
local user to cause a denial of service (crash) or read arbitrary kernel
memory on 64-bit systems (CVE-2006-2448, important)

* a flaw in the netfilter SCTP module when receiving a chunkless packet
that allowed a remote user to cause a denial of service (crash)
(CVE-2006-2934, important)

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-08-10" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3055.html">CVE-2005-3055</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3623.html">CVE-2005-3623</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0038.html">CVE-2006-0038</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0456.html">CVE-2006-0456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0457.html">CVE-2006-0457</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0742.html">CVE-2006-0742</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1052.html">CVE-2006-1052</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1056.html">CVE-2006-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1242.html">CVE-2006-1242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1343.html">CVE-2006-1343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1857.html">CVE-2006-1857</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2275.html">CVE-2006-2275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2446.html">CVE-2006-2446</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2448.html">CVE-2006-2448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2934.html">CVE-2006-2934</cve>
                <bugzilla href="http://bugzilla.redhat.com/141342" id="141342">install hangs on Dell PowerVault 745 with SATA drives (sata_vsc module)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149933" id="149933">fix missing wakeup in ipc/sem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151981" id="151981">udevd fails to create /dev files after misc_register</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154984" id="154984">Sound Blaster Audigy 2 Value audio does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155926" id="155926">[RHEL4-U2][Diskdump] OS_INIT dump function is broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156145" id="156145">kernel may oops if more  than 4k worth of string data returned in /proc/devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156663" id="156663">Can't install from SATA CD/DVD drive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157404" id="157404">Loss of SATA ICH device hangs RAID1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157902" id="157902">[PATCH] ata_piix fails on some ICH7 hardware</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158989" id="158989">snd-nm256 module hangs Dell Latitude CSx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165113" id="165113">kernel build broken when 4KSTACKS disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165245" id="165245">EHCI Host driver violates USB2.0 Specification leading to device failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166541" id="166541">mdadm --grow infinite resync</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168285" id="168285">No (useful) logging of parameters to execve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169260" id="169260">CVE-2005-3055 async usb devio oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169456" id="169456">COMM_LOST problem with SCTP stream socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169600" id="169600">SMP kernel crash when use as LVS router</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170143" id="170143">rm command hangs when removing a symlink on ext2 loop filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170434" id="170434">Deadlock in fc_target_unblock while shutting down the system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171304" id="171304">sata_promise: missing PCI ID for SATA300 TX4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171507" id="171507">RHEL4 U3 feature request: add some new lm sensors modules to the i2c module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171645" id="171645">Oops kernel NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171740" id="171740">ipw2100 modules crashes and restarts whenever in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172199" id="172199">Spurious keyboard repeats and clock is fast</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172696" id="172696">kernel panic after a few hours/days of operation with pulse</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173193" id="173193">vmalloc limited to 64Mb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173489" id="173489">kernel panics when rebooting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173843" id="173843">Kernel panic with this comment: &lt;4>VFS: Busy inodes after unmount. Self-destruct in 5 seconds.  Have a nice day...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173895" id="173895">Kernel panic on install on 64BG EM64T</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174019" id="174019">TG3 driver crashes with BCM4704C chipset with heavy traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174155" id="174155">Documentation mismatch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174470" id="174470">RFE: tg3 support for Broadcom 5751 PCIe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174639" id="174639">System hangs with kernel panic when using current 3ware drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174671" id="174671">[PATCH] bonding: don't drop non-VLAN traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174990" id="174990">CRM# 717690: crash possibly related to ipvsadm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175616" id="175616">[RHEL 4 U2] kernel panic on EM64T with long cmdline args</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175763" id="175763">misleading overcommit_memory reference in Documentation/filesystems/proc.txt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175778" id="175778">Accessing automounted directories can cause a process to hang forever</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175854" id="175854">[RHEL4-U3] Checking dump partition fails when a swap partition whose size is less than memory size is configured for diskdump.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176107" id="176107">sata-nv crashes on multiple SATA disks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176173" id="176173">The hash.h hash_long function, when used on a 64 bit machine, ignores  many of the middle-order bits.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176361" id="176361">io_setup() fails for 32bit tasks in x86-64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176601" id="176601">Oprofile unsupported recent Pentium4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/176612" id="176612">xw6400 System panic while installing RHEL4-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177439" id="177439">SELinux MLS compatibility</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177509" id="177509">No i915 DRM module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178084" id="178084">Last AIO read of a file opened with O_DIRECT returns wrong length</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178720" id="178720">O_DIRECT bug when reading last block of sparse file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178845" id="178845">RHEL4u4 FEAT: Provide support for Opteron Rev G and Power Now! clean-up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179206" id="179206">Please backport the sata_mv Marvell MV88SX5081 driver?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179334" id="179334">kernel boot can Oops in work queue code when console blanks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179752" id="179752">Request to update lpfc driver in RHEL 4 U4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180028" id="180028">deadlocks on ext2,sync mounted fs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180138" id="180138">kmir_mon worker thread doesn't exit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180195" id="180195">aic7xxx and aic79xx Drivers Don't Support 16-byte CDBs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180568" id="180568">typo in spinlock.h? line 407</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180621" id="180621">ipv6 ready logo-P1 ND Test24 fails- RA Lifetime=5 not understood</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/180958" id="180958">[RHEL4] MCE arg parsing broken on x86-64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181457" id="181457">Console redirection on DRAC 3 results in repeated key strokes (P1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181475" id="181475">lpfc driver: add managment ioctl module to kernel tree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181780" id="181780">Gettimeofday() timer related slowdown and scaling issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181793" id="181793">add MCP51/ NVidia 430 IDE support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181869" id="181869">Error given when duplicate non-updateable key (eg: keyring) added</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181870" id="181870">Key quota handling incorrect in allocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181879" id="181879">CVE-2006-0457 Key syscalls use get length of strings before copying, and assume terminating NUL copied from userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/181881" id="181881">CVE-2006-0456 s390/s390x strnlen_user() is broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182137" id="182137">NFS lockd recovery is broken in U3 due to missing code.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182684" id="182684">[EMC/Oracle RHEL 4.4] ISCSI MODULE SHOWS MULTIPLE DEVICES FOR A SINGLE LUN IN RHEL 4.0 U2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182726" id="182726">Possible hang when ptracing and using hugepages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183392" id="183392">[RHEL4] [RFE] Add diskdump capability to IDE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183416" id="183416">DoS attack possible via nfsservctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183463" id="183463">CVE-2006-0742 Bug in IA64 unaligned access handler causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183661" id="183661">ramfs: update dir mtime and ctime</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183664" id="183664">dm: make sure don't give out the same minor number twice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184208" id="184208">Large LUNS can't be seen with Hitachi Open- SAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184254" id="184254">PCI interrupts on ioapic pins 0-15 always get "legacy" IRQs.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184535" id="184535">[BETA RHEL4 U3] brokenness in cfq_dispatch_requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184583" id="184583">Kernel should export number and state of local APICs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185043" id="185043">CVE-2005-3623 ACL setting on read-only fs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185289" id="185289">CVE-2006-1052 SELinux flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185431" id="185431">kernel dm: bad argument count check in dm-log.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185444" id="185444">kernel dm: missing bdput</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185445" id="185445">kernel dm: fix free_dev del_gendisk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185447" id="185447">kernel dm: flush queued bios if suspend is interrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185450" id="185450">kernel dm: log bitset fix BE find_next_zero_bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185454" id="185454">kernel device-mapper mirroring: table output incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185455" id="185455">kernel dm snapshots: replace siblings list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185456" id="185456">kernel dm mirroring: suspend operation is not well behaved</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185459" id="185459">kernel dm snapshots: fix invalidation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185468" id="185468">kernel dm: striped access beyond end of device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185754" id="185754">[RHEL4 U3] kernel dm mirror: unrelated mirror devices stall if any log device fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185782" id="185782">[RHEL4 U3] device-mapper mirror: Data corruption if the default mirror fails during recovery.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185785" id="185785">[RHEL4 U3] device-mapper mirror: Data corruption by temporal errors during recovery.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185991" id="185991">kernel dm: bio split bvec fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186004" id="186004">[RHEL4 U3] device-mapper mirror: Write failure region becomes in-sync when suspension.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186057" id="186057">CVE-2006-1242 Linux zero IP ID vulnerability?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186066" id="186066">Connectathon tests fail against newer Irix server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186071" id="186071">NFSD fails SETCLIENTID_CONFIRM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186104" id="186104">kernel dm mirror: lvs Copy% overs 100% by lvreduce/lvresize.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186242" id="186242">CVE-2006-1343 Small information leak in SO_ORIGINAL_DST</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186295" id="186295">CVE-2006-0038 netfilters do_replace() overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186316" id="186316">nvidia cache aliasing problem: change_page_attr drops GLOBAL bit from executable kernel pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186564" id="186564">ACPI 2.0 systems with no XSDT fail to boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186751" id="186751">kernel problem to deal with 3ware 9500SX-12 RAID cards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187249" id="187249">[RHEL4 U3] dm-mirror: read stalls if all mirrors failed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187494" id="187494">CVE-2006-2275 SCTP traffic probably never resumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187498" id="187498">diskdump_sysfs_store() needs to check sscanf retval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187500" id="187500">diskdump_sysfs_store() should check  partition number</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187501" id="187501">device_to_gendisk() is lacking mntput(nd.mnt) on exit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187502" id="187502">diskdump - device_to_gendisk() is both racy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187910" id="187910">CVE-2006-1056 FPU Information leak on i386/x86-64 on AMD CPUs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187951" id="187951">Replication failover fails if the NFS permissions are incorrect on one of the servers...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188080" id="188080">kernel dm snapshots: Incorrect processing of incorrect chunk size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188141" id="188141">Kernel appears too conservative in memory use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188296" id="188296">tlb_clear_slave races with tlb_choose_channel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188912" id="188912">Update Qlogic qla2xxx driver in RHEL 4 U4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189127" id="189127">Trouble with recent module - one packet is seen more than one time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189198" id="189198">VLAN not working on initial startup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189279" id="189279">[Stratus RHEL4 U4 bug] unchecked error path in usb_alloc_dev can lead to an Oops.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189390" id="189390">RHEL4-U3: openipmi: startup race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189392" id="189392">Submit Promise RHEL4 driver in-box to RHEL4 CD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189393" id="189393">Submit Promise RHEL4 driver in-box to RHEL4 CD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189397" id="189397">Submit Promise RHEL4 driver in-box to RHEL4 CD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189797" id="189797">dm: Fix mapped device references</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190576" id="190576">REGRESSION: kabi breakage on ia64_mv</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191138" id="191138">CVE-2006-0742 Bug in IA64 unaligned access handler causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191139" id="191139">installer does not see SATA HDs attached to JMB360 chipset which in legacy mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191141" id="191141">MCE arg parsing broken on x86-64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191723" id="191723">device-mapper mirror: Need proper notification of sync status chage on write failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191847" id="191847">REGRESSION: kernel-2.6.9.36 does not boot on ALTIX systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192098" id="192098">Fix problems with MSI-X on 64-bit platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192635" id="192635">CVE-2006-1857 SCTP HB-ACK chunk overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192779" id="192779">CVE-2006-2446 LTC20512-kernel BUG in __kfree_skb while running TCP+Kernel stress</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193230" id="193230">RFE: add pci ids for atiixp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193696" id="193696">Not using all available system memory - swapping too aggressive - high load average (iowait)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193728" id="193728">A write to a cluster mirror volume not in sync will hang and also cause the sync to hang as well</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193838" id="193838">gettimeofday goes backwards on IBM x460 merged servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/194215" id="194215">CVE-2006-2448 missing access_ok checks in powerpc signal*.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/194533" id="194533">veritas storage foundation 32bit apps crash in glibc during post-process installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/195002" id="195002">RHEL4 U4 i386 partner beta will not install on ES7000/one</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/195254" id="195254">HP xw9400 network card not getting seen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/195502" id="195502">Regression: cluster mirror creation cmd hangs even though mirror gets created</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196512" id="196512">VLANs, tg3 driver, and 2.6.9-34.EL kernel update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196712" id="196712">O=/objdir builds fail for out-of-tree builds with 2.6.9-39.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/197387" id="197387">CVE-2006-2934 SCTP netfilter DoS with chunkless packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/198321" id="198321">kernel freeze at "kernel BUG at kernel/timer.c:420!"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/198892" id="198892">kernel deadlock on reading /proc/meminfo on 4 CPU's at the same time</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575002" comment="kernel is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575018" comment="kernel-doc is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575004" comment="kernel-devel is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575010" comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575014" comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575006" comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060132009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575016" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060575012" comment="kernel-smp is earlier than 0:2.6.9-42.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060576" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0576: kdebase security fix (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0576-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0576.html" />
          <reference source="CVE" ref_id="CVE-2006-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2933.html" />
    
    <description>The kdebase packages provide the core applications for KDE, the K Desktop
Environment.

A flaw was found in KDE where the kdesktop_lock process sometimes
failed to terminate properly.  This issue could either block the user's
ability to manually lock the desktop or prevent the screensaver to
activate, both of which could have a security impact for users who rely on
these functionalities. 
(CVE-2006-2933)

Please note that this issue only affected Red Hat Enterprise Linux 3.

All users of kdebase should upgrade to these updated packages, which
contain a patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-25" />
        <updated date="2006-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2933.html">CVE-2006-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/177755" id="177755">CVE-2006-2933 occasionally KDE screensaver fails to start</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060576002" comment="kdebase is earlier than 6:3.1.3-5.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060576004" comment="kdebase-devel is earlier than 6:3.1.3-5.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060577" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0577: mutt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0577-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0577.html" />
          <reference source="CVE" ref_id="CVE-2006-3242" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3242.html" />
    
    <description>Mutt is a text-mode mail user agent.

A buffer overflow flaw was found in the way Mutt processes an overly
long namespace from a malicious imap server.  In order to exploit this
flaw a user would have to use Mutt to connect to a malicious IMAP server.
(CVE-2006-3242)

Users of Mutt are advised to upgrade to these erratum packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-12" />
        <updated date="2006-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3242.html">CVE-2006-3242</cve>
                <bugzilla href="http://bugzilla.redhat.com/197151" id="197151">CVE-2006-3242 Mutt IMAP namespace buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060577002" comment="mutt is earlier than 5:1.4.1-3.5.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050003" comment="mutt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060577005" comment="mutt is earlier than 5:1.4.1-11.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050003" comment="mutt is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060578" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0578: seamonkey security update (was mozilla) (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0578-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0578.html" />
          <reference source="CVE" ref_id="CVE-2006-2779" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2779.html" />
          <reference source="CVE" ref_id="CVE-2006-2780" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2780.html" />
          <reference source="CVE" ref_id="CVE-2006-2781" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2781.html" />
          <reference source="CVE" ref_id="CVE-2006-2783" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2783.html" />
          <reference source="CVE" ref_id="CVE-2006-2782" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2782.html" />
          <reference source="CVE" ref_id="CVE-2006-2778" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2778.html" />
          <reference source="CVE" ref_id="CVE-2006-2776" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2776.html" />
          <reference source="CVE" ref_id="CVE-2006-2784" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2784.html" />
          <reference source="CVE" ref_id="CVE-2006-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2785.html" />
          <reference source="CVE" ref_id="CVE-2006-2786" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2786.html" />
          <reference source="CVE" ref_id="CVE-2006-2787" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2787.html" />
          <reference source="CVE" ref_id="CVE-2006-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2788.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

The Mozilla Foundation has discontinued support for the Mozilla Suite. This
update deprecates the Mozilla Suite in Red Hat Enterprise Linux 3 in favor
of the supported SeaMonkey Suite.

This update also resolves a number of outstanding Mozilla security issues:

Several flaws were found in the way Mozilla processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787)

Several denial of service flaws were found in the way Mozilla processed
certain web content. A malicious web page could crash firefox or possibly
execute arbitrary code. These issues to date were not proven to be
exploitable, but do show evidence of memory corruption. (CVE-2006-2779,
CVE-2006-2780)

A double-free flaw was found in the way Mozilla-mail displayed malformed
inline vcard attachments. If a victim viewed an email message containing
a carefully crafted vcard it could execute arbitrary code as the user
running Mozilla-mail. (CVE-2006-2781) 

A cross site scripting flaw was found in the way Mozilla processed Unicode
Byte-order-Mark (BOM) markers in UTF-8 web pages. A malicious web page
could execute a script within the browser that a web input sanitizer could
miss due to a malformed "script" tag. (CVE-2006-2783)

A form file upload flaw was found in the way Mozilla handled javascript
input object mutation. A malicious web page could upload an arbitrary local
file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Mozilla called the
crypto.signText() javascript function. A malicious web page could crash the
browser if the victim had a client certificate loaded. (CVE-2006-2778)

Two HTTP response smuggling flaws were found in the way Mozilla processed
certain invalid HTTP response headers. A malicious web site could return
specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page it could execute
arbitrary code as the user running Mozilla. (CVE-2006-2788)

Users of Mozilla are advised to upgrade to this update, which contains
SeaMonkey version 1.0.2 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-20" />
        <updated date="2006-07-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2779.html">CVE-2006-2779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2780.html">CVE-2006-2780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2781.html">CVE-2006-2781</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2783.html">CVE-2006-2783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2782.html">CVE-2006-2782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2778.html">CVE-2006-2778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2776.html">CVE-2006-2776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2784.html">CVE-2006-2784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2785.html">CVE-2006-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2786.html">CVE-2006-2786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2787.html">CVE-2006-2787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2788.html">CVE-2006-2788</cve>
                <bugzilla href="http://bugzilla.redhat.com/196971" id="196971">CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/198683" id="198683">CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2780, CVE-2006-2781)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578014" comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578015" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578018" comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578012" comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578013" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578016" comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578017" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578002" comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578010" comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578020" comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578021" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578006" comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578007" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578004" comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060578008" comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060582" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0582: kdebase security fix (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0582-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0582.html" />
          <reference source="CVE" ref_id="CVE-2005-2494" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2494.html" />
    
    <description>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include the file manager Konqueror.

Ilja van Sprundel discovered a lock file handling flaw in kcheckpass.  If
the directory /var/lock is writable by a user who is allowed to run
kcheckpass, that user could gain root privileges.  In Red Hat Enterprise
Linux, the /var/lock directory is not writable by users and therefore this
flaw could only have been exploited if the permissions on that directory
have been badly configured.  A patch to block this issue has been included
in this update.  (CVE-2005-2494)

The following bugs have also been addressed:

- kstart --tosystray does not send the window to the system tray in Kicker

- When the customer enters or selects URLs in Firefox's address field, the
desktop freezes for a couple of seconds

- fish kioslave is broken on 64-bit systems

All users of kdebase should upgrade to these updated packages, which
contain patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-08-10" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2494.html">CVE-2005-2494</cve>
                <bugzilla href="http://bugzilla.redhat.com/166995" id="166995">CVE-2005-2494 kcheckpass privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060582002" comment="kdebase is earlier than 6:3.3.1-5.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060582004" comment="kdebase-devel is earlier than 6:3.3.1-5.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060591" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0591: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0591-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0591.html" />
          <reference source="CVE" ref_id="CVE-2006-3403" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3403.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service bug was found in the way the smbd daemon tracks active
connections to shares. It was possible for a remote attacker to cause the
smbd daemon to consume a large amount of system memory by sending carefully
crafted smb requests. (CVE-2006-3403)

Users of Samba are advised to upgrade to these packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-25" />
        <updated date="2006-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3403.html">CVE-2006-3403</cve>
                <bugzilla href="http://bugzilla.redhat.com/197836" id="197836">CVE-2006-3403 Samba denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591006" comment="samba-client is earlier than 0:3.0.9-1.3E.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591008" comment="samba-common is earlier than 0:3.0.9-1.3E.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591002" comment="samba is earlier than 0:3.0.9-1.3E.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591004" comment="samba-swat is earlier than 0:3.0.9-1.3E.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591014" comment="samba-client is earlier than 0:3.0.10-1.4E.6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591013" comment="samba-common is earlier than 0:3.0.10-1.4E.6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591011" comment="samba is earlier than 0:3.0.10-1.4E.6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060591012" comment="samba-swat is earlier than 0:3.0.10-1.4E.6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060597" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0597: libwmf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0597-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0597.html" />
          <reference source="CVE" ref_id="CVE-2006-3376" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3376.html" />
    
    <description>Libwmf is a library for reading and converting Windows MetaFile vector
graphics (WMF).  Libwmf is used by packages such as The GIMP and ImageMagick.

An integer overflow flaw was discovered in libwmf.  An attacker could
create a carefully crafted WMF flaw that could execute arbitrary code if
opened by a victim.  (CVE-2006-3376).

Users of libwmf should update to these packages which contain a backported
security patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-07-18" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3376.html">CVE-2006-3376</cve>
                <bugzilla href="http://bugzilla.redhat.com/198290" id="198290">CVE-2006-3376 libwmf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060597002" comment="libwmf is earlier than 0:0.2.8.3-5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060597003" comment="libwmf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060597004" comment="libwmf-devel is earlier than 0:0.2.8.3-5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060597005" comment="libwmf-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060598" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0598: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0598-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0598.html" />
          <reference source="CVE" ref_id="CVE-2006-3404" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3404.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Henning Makholm discovered a buffer overflow bug in The GIMP XCF file
loader. An attacker could create a carefully crafted image that could
execute arbitrary code if opened by a victim.  (CVE-2006-3404)

Please note that this issue did not affect the gimp packages in Red Hat
Enterprise Linux 2.1, or 3.

Users of The GIMP should update to these erratum packages which contain a
backported fix to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-18" />
        <updated date="2006-07-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3404.html">CVE-2006-3404</cve>
                <bugzilla href="http://bugzilla.redhat.com/198269" id="198269">CVE-2006-3404 gimp xcf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060598004" comment="gimp-devel is earlier than 1:2.0.5-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060598005" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060598002" comment="gimp is earlier than 1:2.0.5-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060598003" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060600" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0600: mailman security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0600-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0600.html" />
          <reference source="CVE" ref_id="CVE-2006-2941" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2941.html" />
          <reference source="CVE" ref_id="CVE-2006-3636" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3636.html" />
    
    <description>Mailman is a program used to help manage email discussion lists.

A flaw was found in the way Mailman handled MIME multipart messages. An
attacker could send a carefully crafted MIME multipart email message to a
mailing list run by Mailman which caused that particular mailing list
to stop working.  (CVE-2006-2941)

Several cross-site scripting (XSS) issues were found in Mailman.  An
attacker could exploit these issues to perform cross-site scripting attacks
against the Mailman administrator.  (CVE-2006-3636)

Red Hat would like to thank Barry Warsaw for disclosing these vulnerabilities.

Users of Mailman should upgrade to these updated packages, which contain
backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-09-06" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2941.html">CVE-2006-2941</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3636.html">CVE-2006-3636</cve>
                <bugzilla href="http://bugzilla.redhat.com/198344" id="198344">CVE-2006-2941 Mailman DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/203704" id="203704">CVE-2006-3636 Mailman XSS issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060600002" comment="mailman is earlier than 3:2.1.5.1-25.rhel3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060600005" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060602" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0602: wireshark security update (was ethereal) (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0602-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0602.html" />
          <reference source="CVE" ref_id="CVE-2006-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3627.html" />
          <reference source="CVE" ref_id="CVE-2006-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3628.html" />
          <reference source="CVE" ref_id="CVE-2006-3629" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3629.html" />
          <reference source="CVE" ref_id="CVE-2006-3630" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3630.html" />
          <reference source="CVE" ref_id="CVE-2006-3631" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3631.html" />
          <reference source="CVE" ref_id="CVE-2006-3632" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3632.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

In May 2006, Ethereal changed its name to Wireshark.  This update
deprecates the Ethereal packages in Red Hat Enterprise Linux 2.1, 3, and 4
in favor of the supported Wireshark packages.

Several denial of service bugs were found in Ethereal's protocol
dissectors. It was possible for Ethereal to crash or stop responding if it
read a malformed packet off the network.  (CVE-2006-3627, CVE-2006-3629,
CVE-2006-3631)

Several buffer overflow bugs were found in Ethereal's ANSI MAP, NCP NMAS,
and NDPStelnet dissectors. It was possible for Ethereal to crash or execute
arbitrary code if it read a malformed packet off the network.
(CVE-2006-3630, CVE-2006-3632)

Several format string bugs were found in Ethereal's Checkpoint FW-1, MQ,
XML, and NTP dissectors. It was possible for Ethereal to crash or execute
arbitrary code if it read a malformed packet off the network. (CVE-2006-3628)

Users of Ethereal should upgrade to these updated packages containing
Wireshark version 0.99.2, which is not vulnerable to these issues</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-08-16" />
        <updated date="2006-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3627.html">CVE-2006-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3628.html">CVE-2006-3628</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3629.html">CVE-2006-3629</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3630.html">CVE-2006-3630</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3631.html">CVE-2006-3631</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3632.html">CVE-2006-3632</cve>
                <bugzilla href="http://bugzilla.redhat.com/199231" id="199231">Replace (EOL) Ethereal with Wireshark</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/199232" id="199232">CVE-2006-3627 Mulitple security issues (CVE-2006-3628 CVE-2006-3629 CVE-2006-3630 CVE-2006-3631 CVE-2006-3632)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060602002" comment="wireshark is earlier than 0:0.99.2-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060602003" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060602004" comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060602005" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060602007" comment="wireshark is earlier than 0:0.99.2-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060602003" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060602008" comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060602005" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060603" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0603: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0603-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0603.html" />
          <reference source="CVE" ref_id="CVE-2006-2656" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2656.html" />
          <reference source="CVE" ref_id="CVE-2006-3459" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3459.html" />
          <reference source="CVE" ref_id="CVE-2006-3460" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3460.html" />
          <reference source="CVE" ref_id="CVE-2006-3461" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3461.html" />
          <reference source="CVE" ref_id="CVE-2006-3462" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3462.html" />
          <reference source="CVE" ref_id="CVE-2006-3463" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3463.html" />
          <reference source="CVE" ref_id="CVE-2006-3464" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3464.html" />
          <reference source="CVE" ref_id="CVE-2006-3465" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3465.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) files.

Tavis Ormandy of Google discovered a number of flaws in libtiff during a
security audit.  An attacker could create a carefully crafted TIFF file in
such a way that it was possible to cause an application linked with libtiff
to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460,
CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465)

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2006-08-02" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2656.html">CVE-2006-2656</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3459.html">CVE-2006-3459</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3460.html">CVE-2006-3460</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3461.html">CVE-2006-3461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3462.html">CVE-2006-3462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3463.html">CVE-2006-3463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3464.html">CVE-2006-3464</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3465.html">CVE-2006-3465</cve>
                <bugzilla href="http://bugzilla.redhat.com/199111" id="199111">CVE-2006-3459 Multiple libtiff flaws (CVE-2006-3460 CVE-2006-3461 CVE-2006-3462 CVE-2006-3463 CVE-2006-3464 CVE-2006-3465)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060603002" comment="libtiff is earlier than 0:3.5.7-25.el3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060603004" comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060603007" comment="libtiff is earlier than 0:3.6.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060603008" comment="libtiff-devel is earlier than 0:3.6.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060604" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0604: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0604-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0604.html" />
          <reference source="CVE" ref_id="CVE-2006-3694" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3694.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming. 

A number of flaws were found in the safe-level restrictions in Ruby.  It
was possible for an attacker to create a carefully crafted malicious script
that can allow the bypass of certain safe-level restrictions. (CVE-2006-3694)

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-27" />
        <updated date="2006-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3694.html">CVE-2006-3694</cve>
                <bugzilla href="http://bugzilla.redhat.com/199539" id="199539">CVE-2006-3694 Insecure operations in the certain safe-level restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/199545" id="199545">CVE-2006-3694 ruby safe-level bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604014" comment="irb is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604004" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604010" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604012" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604006" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604002" comment="ruby is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604008" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604022" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604021" comment="irb is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604020" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604023" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604019" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604017" comment="ruby is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060604018" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060605" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0605: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0605-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0605.html" />
          <reference source="CVE" ref_id="CVE-2006-3813" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3813.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a flaw in sperl, the Perl setuid wrapper, which
can cause debugging information to be logged to arbitrary files. By setting
an environment variable, a local user could cause sperl to create, as root,
files with arbitrary filenames, or append the debugging information to
existing files. (CVE-2005-0155)

A fix for this issue was first included in the update RHSA-2005:103
released in February 2005.  However the patch to correct this issue was
dropped from the update RHSA-2005:674 made in October 2005.  This
regression has been assigned CVE-2006-3813.

Users of Perl are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-08-10" />
        <updated date="2006-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3813.html">CVE-2006-3813</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060605004" comment="perl-suidperl is earlier than 3:5.8.5-36.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060605002" comment="perl is earlier than 3:5.8.5-36.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060608" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0608: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0608-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0608.html" />
          <reference source="CVE" ref_id="CVE-2006-3801" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3801.html" />
          <reference source="CVE" ref_id="CVE-2006-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3677.html" />
          <reference source="CVE" ref_id="CVE-2006-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3113.html" />
          <reference source="CVE" ref_id="CVE-2006-3802" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3802.html" />
          <reference source="CVE" ref_id="CVE-2006-3803" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3803.html" />
          <reference source="CVE" ref_id="CVE-2006-3804" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3804.html" />
          <reference source="CVE" ref_id="CVE-2006-3805" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3805.html" />
          <reference source="CVE" ref_id="CVE-2006-3806" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3806.html" />
          <reference source="CVE" ref_id="CVE-2006-3807" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3807.html" />
          <reference source="CVE" ref_id="CVE-2006-3808" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3808.html" />
          <reference source="CVE" ref_id="CVE-2006-3809" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3809.html" />
          <reference source="CVE" ref_id="CVE-2006-3810" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3810.html" />
          <reference source="CVE" ref_id="CVE-2006-3811" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3811.html" />
          <reference source="CVE" ref_id="CVE-2006-3812" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3812.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3807,
CVE-2006-3809, CVE-2006-3812)

Several denial of service flaws were found in the way SeaMonkey processed
certain web content. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running SeaMonkey.
(CVE-2006-3801, CVE-2006-3677, CVE-2006-3113, CVE-2006-3803, CVE-2006-3805,
CVE-2006-3806, CVE-2006-3811)

A buffer overflow flaw was found in the way SeaMonkey Messenger displayed
malformed inline vcard attachments. If a victim viewed an email message
containing a carefully crafted vcard, it was possible to execute arbitrary
code as the user running SeaMonkey Messenger. (CVE-2006-3804)

Several flaws were found in the way SeaMonkey processed certain javascript
actions. A malicious web page could conduct a cross-site scripting attack
or steal sensitive information (such as cookies owned by other domains).
(CVE-2006-3802, CVE-2006-3810)

A flaw was found in the way SeaMonkey processed Proxy AutoConfig scripts. A
malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3808)

Users of SeaMonkey are advised to upgrade to this update, which contains
SeaMonkey version 1.0.3 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-27" />
        <updated date="2006-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3801.html">CVE-2006-3801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3677.html">CVE-2006-3677</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3113.html">CVE-2006-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3802.html">CVE-2006-3802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3803.html">CVE-2006-3803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3804.html">CVE-2006-3804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3805.html">CVE-2006-3805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3806.html">CVE-2006-3806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3807.html">CVE-2006-3807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3808.html">CVE-2006-3808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3809.html">CVE-2006-3809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3810.html">CVE-2006-3810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3811.html">CVE-2006-3811</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3812.html">CVE-2006-3812</cve>
                <bugzilla href="http://bugzilla.redhat.com/200253" id="200253">CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608004" comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578015" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608012" comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578013" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608006" comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608010" comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578017" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608002" comment="seamonkey is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608008" comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608020" comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608018" comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578021" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608014" comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578007" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060608016" comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060609" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0609: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0609-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0609.html" />
          <reference source="CVE" ref_id="CVE-2006-2779" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2779.html" />
          <reference source="CVE" ref_id="CVE-2006-2780" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2780.html" />
          <reference source="CVE" ref_id="CVE-2006-2781" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2781.html" />
          <reference source="CVE" ref_id="CVE-2006-2783" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2783.html" />
          <reference source="CVE" ref_id="CVE-2006-2782" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2782.html" />
          <reference source="CVE" ref_id="CVE-2006-2778" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2778.html" />
          <reference source="CVE" ref_id="CVE-2006-2776" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2776.html" />
          <reference source="CVE" ref_id="CVE-2006-2784" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2784.html" />
          <reference source="CVE" ref_id="CVE-2006-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2785.html" />
          <reference source="CVE" ref_id="CVE-2006-2786" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2786.html" />
          <reference source="CVE" ref_id="CVE-2006-2787" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2787.html" />
          <reference source="CVE" ref_id="CVE-2006-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2788.html" />
          <reference source="CVE" ref_id="CVE-2006-3801" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3801.html" />
          <reference source="CVE" ref_id="CVE-2006-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3677.html" />
          <reference source="CVE" ref_id="CVE-2006-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3113.html" />
          <reference source="CVE" ref_id="CVE-2006-3802" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3802.html" />
          <reference source="CVE" ref_id="CVE-2006-3803" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3803.html" />
          <reference source="CVE" ref_id="CVE-2006-3804" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3804.html" />
          <reference source="CVE" ref_id="CVE-2006-3805" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3805.html" />
          <reference source="CVE" ref_id="CVE-2006-3806" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3806.html" />
          <reference source="CVE" ref_id="CVE-2006-3807" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3807.html" />
          <reference source="CVE" ref_id="CVE-2006-3808" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3808.html" />
          <reference source="CVE" ref_id="CVE-2006-3809" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3809.html" />
          <reference source="CVE" ref_id="CVE-2006-3810" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3810.html" />
          <reference source="CVE" ref_id="CVE-2006-3811" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3811.html" />
          <reference source="CVE" ref_id="CVE-2006-3812" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3812.html" />
    
    <description>Seamonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

The Mozilla Foundation has discontinued support for the Mozilla Suite. This
update deprecates the Mozilla Suite in Red Hat Enterprise Linux 4 in
favor of the supported Seamonkey Suite.

This update also resolves a number of outstanding Mozilla security issues:

Several flaws were found in the way Seamonkey processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787, CVE-2006-3807, CVE-2006-3809,
CVE-2006-3812)

Several denial of service flaws were found in the way Seamonkey processed
certain web content. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running Seamonkey.
(CVE-2006-2779, CVE-2006-2780, CVE-2006-3801, CVE-2006-3677, CVE-2006-3113,
CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3811)

Two flaws were found in the way Seamonkey-mail displayed malformed
inline vcard attachments. If a victim viewed an email message containing
a carefully crafted vcard it was possible to execute arbitrary code as the
user running Mozilla-mail. (CVE-2006-2781, CVE-2006-3804)

A cross-site scripting flaw was found in the way Seamonkey processed
Unicode Byte-Order-Mark (BOM) markers in UTF-8 web pages. A malicious web
page could execute a script within the browser that a web input sanitizer
could miss due to a malformed "script" tag. (CVE-2006-2783)

Several flaws were found in the way Seamonkey processed certain javascript
actions. A malicious web page could conduct a cross-site scripting attack
or steal sensitive information (such as cookies owned by other domains).
(CVE-2006-3802, CVE-2006-3810)

A form file upload flaw was found in the way Seamonkey handled javascript
input object mutation. A malicious web page could upload an arbitrary local
file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Seamonkey called the
crypto.signText() javascript function. A malicious web page could crash the
browser if the victim had a client certificate loaded. (CVE-2006-2778)

Two HTTP response smuggling flaws were found in the way Seamonkey processed
certain invalid HTTP response headers. A malicious web site could return
specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A flaw was found in the way Seamonkey processed Proxy AutoConfig scripts. A
malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3808)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page, it was possible
to execute arbitrary code as the user running Mozilla. (CVE-2006-2788)

Users of Mozilla are advised to upgrade to this update, which contains
Seamonkey version 1.0.3 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-08-02" />
        <updated date="2006-08-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2779.html">CVE-2006-2779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2780.html">CVE-2006-2780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2781.html">CVE-2006-2781</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2783.html">CVE-2006-2783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2782.html">CVE-2006-2782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2778.html">CVE-2006-2778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2776.html">CVE-2006-2776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2784.html">CVE-2006-2784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2785.html">CVE-2006-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2786.html">CVE-2006-2786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2787.html">CVE-2006-2787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2788.html">CVE-2006-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3801.html">CVE-2006-3801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3677.html">CVE-2006-3677</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3113.html">CVE-2006-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3802.html">CVE-2006-3802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3803.html">CVE-2006-3803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3804.html">CVE-2006-3804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3805.html">CVE-2006-3805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3806.html">CVE-2006-3806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3807.html">CVE-2006-3807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3808.html">CVE-2006-3808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3809.html">CVE-2006-3809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3810.html">CVE-2006-3810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3811.html">CVE-2006-3811</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3812.html">CVE-2006-3812</cve>
                <bugzilla href="http://bugzilla.redhat.com/193906" id="193906">CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2780, CVE-2006-2781)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196969" id="196969">CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200161" id="200161">CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609006" comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578015" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609020" comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609014" comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578013" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609010" comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578017" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609002" comment="seamonkey is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609004" comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609018" comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609012" comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578007" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609008" comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578021" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609016" comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20060578009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609022" comment="devhelp is earlier than 0:0.10-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20060609024" comment="devhelp-devel is earlier than 0:0.10-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20060610" version="502" class="patch">
      <metadata>
        <title>RHSA-2006:0610: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2006:0610-01" ref_url="https://rhn.redhat.com/errata/RHSA-2006-0610.html" />
          <reference source="CVE" ref_id="CVE-2006-2779" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2779.html" />
          <reference source="CVE" ref_id="CVE-2006-2780" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2780.html" />
          <reference source="CVE" ref_id="CVE-2006-2783" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2783.html" />
          <reference source="CVE" ref_id="CVE-2006-2782" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2782.html" />
          <reference source="CVE" ref_id="CVE-2006-2778" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2778.html" />
          <reference source="CVE" ref_id="CVE-2006-2776" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2776.html" />
          <reference source="CVE" ref_id="CVE-2006-2784" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2784.html" />
          <reference source="CVE" ref_id="CVE-2006-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2785.html" />
          <reference source="CVE" ref_id="CVE-2006-2786" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2786.html" />
          <reference source="CVE" ref_id="CVE-2006-2787" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2787.html" />
          <reference source="CVE" ref_id="CVE-2006-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2788.html" />
          <reference source="CVE" ref_id="CVE-2006-3801" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3801.html" />
          <reference source="CVE" ref_id="CVE-2006-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3677.html" />
          <reference source="CVE" ref_id="CVE-2006-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3113.html" />
          <reference source="CVE" ref_id="CVE-2006-3802" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3802.html" />
          <reference source="CVE" ref_id="CVE-2006-3803" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3803.html" />
          <reference source="CVE" ref_id="CVE-2006-3805" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3805.html" />
          <reference source="CVE" ref_id="CVE-2006-3806" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3806.html" />
          <reference source="CVE" ref_id="CVE-2006-3807" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3807.html" />
          <reference source="CVE" ref_id="CVE-2006-3808" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3808.html" />
          <reference source="CVE" ref_id="CVE-2006-3809" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3809.html" />
          <reference source="CVE" ref_id="CVE-2006-3810" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3810.html" />
          <reference source="CVE" ref_id="CVE-2006-3811" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3811.html" />
          <reference source="CVE" ref_id="CVE-2006-3812" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3812.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

The Mozilla Foundation has discontinued support for the Mozilla Firefox
1.0 branch. This update deprecates the Mozilla Firefox 1.0 branch in
Red Hat Enterprise Linux 4 in favor of the supported Mozilla Firefox
1.5 branch.

This update also resolves a number of outstanding Firefox security issues:

Several flaws were found in the way Firefox processed certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-2776,
CVE-2006-2784, CVE-2006-2785, CVE-2006-2787, CVE-2006-3807, CVE-2006-3809,
CVE-2006-3812)

Several denial of service flaws were found in the way Firefox processed
certain web content. A malicious web page could crash the browser or
possibly execute arbitrary code as the user running Firefox.
(CVE-2006-2779, CVE-2006-2780, CVE-2006-3801, CVE-2006-3677, CVE-2006-3113,
CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3811)

A cross-site scripting flaw was found in the way Firefox processed
Unicode Byte-Order-Mark (BOM) markers in UTF-8 web pages. A malicious web
page could execute a script within the browser that a web input sanitizer
could miss due to a malformed "script" tag. (CVE-2006-2783)

Several flaws were found in the way Firefox processed certain javascript
actions. A malicious web page could conduct a cross-site scripting attack
or steal sensitive information (such as cookies owned by other domains).
(CVE-2006-3802, CVE-2006-3810)

A form file upload flaw was found in the way Firefox handled javascript
input object mutation. A malicious web page could upload an arbitrary local
file at form submission time without user interaction. (CVE-2006-2782)

A denial of service flaw was found in the way Firefox called the
crypto.signText() javascript function. A malicious web page could crash the
browser if the victim had a client certificate loaded. (CVE-2006-2778)

Two HTTP response smuggling flaws were found in the way Firefox processed
certain invalid HTTP response headers. A malicious web site could return
specially crafted HTTP response headers which may bypass HTTP proxy
restrictions. (CVE-2006-2786)

A flaw was found in the way Firefox processed Proxy AutoConfig scripts. A
malicious Proxy AutoConfig server could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware. (CVE-2006-3808)

A double free flaw was found in the way the nsIX509::getRawDER method was
called. If a victim visited a carefully crafted web page, it was possible
to execute arbitrary code as the user running Firefox. (CVE-2006-2788)

Users of Firefox are advised to upgrade to this update, which contains
Firefox version 1.5.0.5 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-28" />
        <updated date="2006-07-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2779.html">CVE-2006-2779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2780.html">CVE-2006-2780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2783.html">CVE-2006-2783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2782.html">CVE-2006-2782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2778.html">CVE-2006-2778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2776.html">CVE-2006-2776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2784.html">CVE-2006-2784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2785.html">CVE-2006-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2786.html">CVE-2006-2786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2787.html">CVE-2006-2787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2788.html">CVE-2006-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3801.html">CVE-2006-3801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3677.html">CVE-2006-3677</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3113.html">CVE-2006-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3802.html">CVE-2006-3802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3803.html">CVE-2006-3803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3805.html">CVE-2006-3805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3806.html">CVE-2006-3806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3807.html">CVE-2006-3807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3808.html">CVE-2006-3808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3809.html">CVE-2006-3809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3810.html">CVE-2006-3810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3811.html">CVE-2006-3811</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3812.html">CVE-2006-3812</cve>
                <bugzilla href="http://bugzilla.redhat.com/193895" id="193895">CVE-2006-2779 multiple firefox DoS issues (CVE-2006-2780)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/196973" id="196973">CVE-2006-2783 multiple Firefox issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200168" id="200168">CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterpris
