<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2013-06-18T08:05:02</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20030315" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:315: quagga security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:315-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-315.html" />
          <reference source="CVE" ref_id="CVE-2003-0858" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0858.html" />
    
    <description>Quagga is an open source implementation of TCP/IP routing software. 
 
Herbert Xu reported that Quagga can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to
this issue. 
 
Users of Quagga should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel. 
This erratum also includes quagga-devel and quagga-contrib packages which
were not originally shipped with Red Hat Enterprise Linux 3.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0858.html">CVE-2003-0858</cve>
                <bugzilla href="http://bugzilla.redhat.com/108575" id="108575">CAN-2003-0858  Netlink local DoS: quagga</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315006" comment="quagga-devel is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315007" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315004" comment="quagga-contrib is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315005" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315002" comment="quagga is earlier than 0:0.96.2-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030315003" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030317" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:317: iproute security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-317.html" />
          <reference source="CVE" ref_id="CVE-2003-0856" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0856.html" />
    
    <description>The iproute package contains advanced IP routing and network device
configuration tools.

Herbert Xu reported that iproute can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0856 to
this issue. 
 
Users of iproute should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0856.html">CVE-2003-0856</cve>
                <bugzilla href="http://bugzilla.redhat.com/108573" id="108573">CAN-2003-0856 Netlink local DoS: iproute</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030317002" comment="iproute is earlier than 0:2.4.7-11.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030317003" comment="iproute is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030324" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:324: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-324.html" />
          <reference source="CVE" ref_id="CVE-2003-0925" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0925.html" />
          <reference source="CVE" ref_id="CVE-2003-0926" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0926.html" />
          <reference source="CVE" ref_id="CVE-2003-0927" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0927.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security issues affect Ethereal.  By exploiting these issues,
it may be possible to make Ethereal crash or run arbitrary code by
injecting a purposefully-malformed packet onto the wire or by convincing
someone to read a malformed packet trace file.

A buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers
to cause a denial of service and possibly execute arbitrary code via a
malformed GTP MSISDN string.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2003-0925 to
this issue.

Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of
service (crash) via certain malformed ISAKMP or MEGACO packets.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0926 to this issue.

A heap-based buffer overflow in Ethereal 0.9.15 and earlier allows
remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code via the SOCKS dissector.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0927
to this issue.

Users of Ethereal should update to these erratum packages containing
Ethereal version 0.9.16, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0925.html">CVE-2003-0925</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0926.html">CVE-2003-0926</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0927.html">CVE-2003-0927</cve>
                <bugzilla href="http://bugzilla.redhat.com/109189" id="109189">CAN-2003-0925/6/7 Ethereal 0.9.13 has three exploitable security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030324004" comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030324002" comment="ethereal is earlier than 0:0.9.16-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030334" version="501" class="patch">
      <metadata>
        <title>RHSA-2003:334: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:334-00" ref_url="https://rhn.redhat.com/errata/RHSA-2003-334.html" />
          <reference source="CVE" ref_id="CVE-2003-0859" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0859.html" />
    
    <description>The glibc packages contain GNU libc, which provides standard system libraries.

Herbert Xu reported that various applications can accept spoofed messages
sent on the kernel netlink interface by other users on the local machine.
This could lead to a local denial of service attack. The glibc function
getifaddrs uses netlink and could therefore be vulnerable to this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0859 to this issue.

In addition to the security issues, a number of other bugs were fixed.

Users are advised to upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel
and patches for the various bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-14" />
        <updated date="2003-11-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0859.html">CVE-2003-0859</cve>
                <bugzilla href="http://bugzilla.redhat.com/90402" id="90402">backtrace() is broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/101261" id="101261">getnameinfo fails to to reverse lookup on IPv6 addresses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/103727" id="103727">LD_PROFILE=libc.so.6 and sprof give seg fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/107846" id="107846">locale utility is broken on big-endian 64-bit platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108631" id="108631">LTC5138-NPTL: pthread_condtimedwait hang or mutex_lock hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108634" id="108634">Signal handler installation races with signal, glibc-2.3.2</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334012" comment="glibc-headers is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334004" comment="glibc-common is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334018" comment="nptl-devel is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334008" comment="glibc-devel is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334006" comment="glibc-debug is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334014" comment="glibc-profile is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334002" comment="glibc is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334016" comment="nscd is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030334010" comment="glibc-utils is earlier than 0:2.3.2-95.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030386" version="503" class="patch">
      <metadata>
        <title>RHSA-2003:386: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:386-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-386.html" />
          <reference source="CVE" ref_id="CVE-2003-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0967.html" />
    
    <description>FreeRADIUS is an Internet authentication daemon, which implements the
RADIUS protocol.  It allows Network Access Servers (NAS boxes) to perform
authentication for dial-up users.

The rad_decode function in FreeRADIUS 0.9.2 and earlier allows remote
attackers to cause a denial of service (crash) via a short RADIUS string
attribute with a tag, which causes memcpy to be called with a -1 length
argument, as demonstrated using the Tunnel-Password attribute.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0967 to this issue.
 
Users of FreeRADIUS are advised to upgrade to these erratum packages
containing FreeRADIUS 0.9.3 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0967.html">CVE-2003-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/110901" id="110901">CAN-2003-0967/8 FreeRadius remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386004" comment="freeradius-mysql is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386006" comment="freeradius-postgresql is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386008" comment="freeradius-unixODBC is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030386002" comment="freeradius is earlier than 0:0.9.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030395" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:395: gnupg security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-395.html" />
          <reference source="CVE" ref_id="CVE-2003-0971" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0971.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

Phong Nguyen identified a severe bug in the way GnuPG creates and uses
ElGamal keys, when those keys are used both to sign and encrypt data.  This
vulnerability can be used to trivially recover the private key.  While the
default behavior of GnuPG when generating keys does not lead to the
creation of unsafe keys, by overriding the default settings an unsafe key
could have been created.

If you are using ElGamal keys, you should revoke those keys immediately.

The packages included in this update do not make ElGamal keys safe to use;
they merely include a patch by David Shaw that disables functions that
would generate or use ElGamal keys.

To determine if your key is affected, run the following command to obtain a
list of secret keys that you have on your secret keyring:

gpg --list-secret-keys

The output of this command includes both the size and type of the keys
found, and will look similar to this example:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024D/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

The key length, type, and ID are listed together, separated by a forward
slash.  In the example output above, the key's type is "D" (DSA, sign
and encrypt).  Your key is unsafe if and only if the key type is "G"
(ElGamal, sign and encrypt).  In the above example, the secret key is safe
to use, while the secret key in the following example is not:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024G/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

For more details regarding this issue, as well as instructions on how to
revoke any keys that are unsafe, refer to the advisory available from the
GnuPG web site:

http://www.gnupg.org/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0971.html">CVE-2003-0971</cve>
                <bugzilla href="http://bugzilla.redhat.com/111345" id="111345">CAN-2003-0971 GnuPG ElGamal compromise</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395002" comment="gnupg is earlier than 0:1.2.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030399" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:399: rsync security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:399-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-399.html" />
          <reference source="CVE" ref_id="CVE-2003-0962" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0962.html" />
    
    <description>rsync is a program for sychronizing files over the network.

A heap overflow bug exists in rsync versions prior to 2.5.7.  On machines
where the rsync server has been enabled, a remote attacker could use this
flaw to execute arbitrary code as an unprivileged user.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0962 to this issue.

All users should upgrade to these erratum packages containing version
2.5.7 of rsync, which is not vulnerable to this issue.

NOTE: The rsync server is disabled (off) by default in Red Hat Enterprise
Linux.  To check if the rsync server has been enabled (on), run the
following command:

/sbin/chkconfig --list rsync

If the rsync server has been enabled but is not required, it can be
disabled by running the following command as root:

/sbin/chkconfig rsync off

Red Hat would like to thank the rsync team for their rapid response and
quick fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-04" />
        <updated date="2003-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0962.html">CVE-2003-0962</cve>
                <bugzilla href="http://bugzilla.redhat.com/111474" id="111474">CAN-2003-0962 rsync remote exploit</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399002" comment="rsync is earlier than 0:2.5.7-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030404" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:404: lftp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:404-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-404.html" />
          <reference source="CVE" ref_id="CVE-2003-0963" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0963.html" />
    
    <description>lftp is a command-line file transfer program supporting FTP and HTTP
protocols. 

Ulf Härnhammar discovered a buffer overflow bug in versions of lftp up to
and including 2.6.9.  An attacker could create a carefully crafted
directory on a website such that, if a user connects to that directory
using the lftp client and subsequently issues a 'ls' or 'rels' command, the
attacker could execute arbitrary code on the users machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0963 to this issue.

Users of lftp are advised to upgrade to these erratum packages, which
contain a backported security patch and are not vulnerable to this issue.

Red Hat would like to thank Ulf Härnhammar for discovering and alerting us
to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2003-12-16" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0963.html">CVE-2003-0963</cve>
                <bugzilla href="http://bugzilla.redhat.com/111717" id="111717">CAN-2003-0963 lftp client buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030404002" comment="lftp is earlier than 0:2.6.3-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030404003" comment="lftp is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030416" version="502" class="patch">
      <metadata>
        <title>RHSA-2003:416: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2003:416-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-416.html" />
          <reference source="CVE" ref_id="CVE-2003-0985" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0985.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux
kernel versions 2.4.23 and previous which may allow a local attacker to
gain root privileges.  No exploit is currently available; however, it is
believed that this issue is exploitable (although not trivially.) The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0985 to this issue.

All users of Red Hat Enterprise Linux 3 are advised to upgrade to these
errata packages, which contain a backported security patch that corrects
this issue.

Red Hat would like to thank Paul Starzetz from ISEC for disclosing this
issue as well as Andrea Arcangeli and Solar Designer for working on the patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-07" />
        <updated date="2004-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0985.html">CVE-2003-0985</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416014" comment="kernel-source is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416002" comment="kernel is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416012" comment="kernel-doc is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416018" comment="kernel-hugemem is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416010" comment="kernel-BOOT is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416004" comment="kernel-smp-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416008" comment="kernel-unsupported is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030416006" comment="kernel-smp is earlier than 0:2.4.21-4.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040002" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:002: ethereal security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-002.html" />
          <reference source="CVE" ref_id="CVE-2003-1012" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1012.html" />
          <reference source="CVE" ref_id="CVE-2003-1013" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1013.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Two security issues have been found that affect Ethereal.  By exploiting
these issues it may be possible to make Ethereal crash by injecting an
intentionally malformed packet onto the wire or by convincing someone to
read a malformed packet trace file.  It is not known if these issues could
allow arbitrary code execution.

The SMB dissector in Ethereal before 0.10.0 allows remote attackers to
cause a denial of service via a malformed SMB packet that triggers a
segmentation fault during processing of Selected packets. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-1012 to this issue.

The Q.931 dissector in Ethereal before 0.10.0 allows remote attackers to
cause a denial of service (crash) via a malformed Q.931, which triggers a
null dereference. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-1013 to this issue.

Users of Ethereal should update to these erratum packages containing
Ethereal version 0.10.0, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-05" />
        <updated date="2004-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1012.html">CVE-2003-1012</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1013.html">CVE-2003-1013</cve>
                <bugzilla href="http://bugzilla.redhat.com/112224" id="112224">CAN-2003-1012/3 Ethereal security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040002004" comment="ethereal-gnome is earlier than 0:0.10.0a-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040002002" comment="ethereal is earlier than 0:0.10.0a-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040004" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:004: cvs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-004.html" />
          <reference source="CVE" ref_id="CVE-2002-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-0844.html" />
          <reference source="CVE" ref_id="CVE-2003-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0977.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.  

A flaw was found in versions of CVS prior to 1.11.10 where a malformed
module request could cause the CVS server to attempt to create files or
directories at the root level of the file system.  However, normal file
system permissions would prevent the creation of these misplaced
directories.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0977 to this issue.

Users of CVS are advised to upgrade to these erratum packages, which
contain a patch correcting this issue.

For Red Hat Enterprise Linux 2.1, these updates also fix an off-by-one
overflow in the CVS PreservePermissions code.  The PreservePermissions 
feature is not used by default (and can only be used for local CVS). The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2002-0844 to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-14" />
        <updated date="2004-01-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-0844.html">CVE-2002-0844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0977.html">CVE-2003-0977</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004002" comment="cvs is earlier than 0:1.11.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040005" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:005: kdepim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-005.html" />
          <reference source="CVE" ref_id="CVE-2003-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0988.html" />
    
    <description>The K Desktop Environment (KDE) is a graphical desktop for the X Window
System. The KDE Personal Information Management (kdepim) suite helps you to
organize your mail, tasks, appointments, and contacts. 

The KDE team found a buffer overflow in the file information reader of
VCF files. An attacker could construct a VCF file so that when it was
opened by a victim it would execute arbitrary commands.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0988 to this issue.

Users of kdepim are advised to upgrade to these erratum packages which
contain a backported security patch that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-05" />
        <updated date="2004-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0988.html">CVE-2003-0988</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040005004" comment="kdepim-devel is earlier than 6:3.1.3-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040005005" comment="kdepim-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040005002" comment="kdepim is earlier than 6:3.1.3-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040005003" comment="kdepim is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040008" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:008: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:008-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-008.html" />
          <reference source="CVE" ref_id="CVE-2003-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0989.html" />
          <reference source="CVE" ref_id="CVE-2004-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0055.html" />
          <reference source="CVE" ref_id="CVE-2004-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0057.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic. 

George Bakos discovered flaws in the ISAKMP decoding routines of tcpdump
versions prior to 3.8.1.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0989 to this issue.

Jonathan Heusser discovered an additional flaw in the ISAKMP decoding
routines for tcpdump 3.8.1 and earlier.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0057 to
this issue.

Jonathan Heusser discovered a flaw in the print_attr_string function in the
RADIUS decoding routines for tcpdump 3.8.1 and earlier.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0055 to this issue.

Remote attackers could potentially exploit these issues by sending
carefully-crafted packets to a victim.  If the victim uses tcpdump, these
pakets could result in a denial of service, or possibly execute arbitrary
code as the 'pcap' user.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-07" />
        <updated date="2004-01-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0989.html">CVE-2003-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0055.html">CVE-2004-0055</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0057.html">CVE-2004-0057</cve>
                <bugzilla href="http://bugzilla.redhat.com/113008" id="113008">CAN-2003-0989 tcpdump parsing overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113366" id="113366">CAN-2004-0055 CAN-2004-0057 Two issues found in tpcdump</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008004" comment="libpcap is earlier than 14:0.7.2-7.E3.1" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008002" comment="tcpdump is earlier than 14:3.7.2-7.E3.1" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040008003" comment="arpwatch is earlier than 14:2.1a11-7.E3.1" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040015" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:015: httpd security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:015-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-015.html" />
          <reference source="CVE" ref_id="CVE-2003-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0542.html" />
    
    <description>The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue in the handling of regular expressions from configuration files
was discovered in releases of the Apache HTTP Server version 2.0 prior to
2.0.48. To exploit this issue an attacker would need to have the ability
to write to Apache configuration files such as .htaccess or httpd.conf. A
carefully-crafted configuration file can cause an exploitable buffer
overflow and would allow the attacker to execute arbitrary code in the
context of the server (in default configurations as the 'apache' user).
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0542 to this issue.

Users of the Apache HTTP Server should upgrade to these erratum packages,
which contain backported patches correcting these issues, and are applied
to Apache version 2.0.46.  This update also includes fixes for a number of
minor bugs found in this version of the Apache HTTP Server.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-13" />
        <updated date="2004-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0542.html">CVE-2003-0542</cve>
                <bugzilla href="http://bugzilla.redhat.com/105725" id="105725">long httpd graceful reload times</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110434" id="110434">CAN-2003-0542 local buffer overflow in config file parsing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015006" comment="httpd-devel is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015004" comment="mod_ssl is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040015002" comment="httpd is earlier than 0:2.0.46-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040017" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:017: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 1 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-017.html" />
          <reference source="CVE" ref_id="CVE-2003-0986" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0986.html" />
          <reference source="CVE" ref_id="CVE-2004-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0001.html" />
    
    <description>The Linux kernel handles the basic functions of the operating
system.

This is the first regular kernel update for Red Hat Enterprise
Linux version 3.  It contains a new critical security fix, many
other bug fixes, several device driver updates, and numerous
performance and scalability enhancements.

On AMD64 systems, a fix was made to the eflags checking in
32-bit ptrace emulation that could have allowed local users
to elevate their privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0001 to this issue.

Other bug fixes were made in the following kernel areas:
VM, NPTL, IPC, kernel timer, ext3, NFS, netdump, SCSI,
ACPI, several device drivers, and machine-dependent
support for the x86_64, ppc64, and s390 architectures.

The VM subsystem was improved to better handle extreme
loads and resource contention (such as might occur during
heavy database application usage).  This has resulted in
a significantly reduced possibility of hangs, OOM kills,
and low-mem exhaustion.

Several NPTL fixes were made to resolve POSIX compliance
issues concerning process IDs and thread IDs.  A section
in the Release Notes elaborates on a related issue with
file record locking in multi-threaded applications.

AMD64 kernels are now configured with NUMA support,
S390 kernels now have CONFIG_BLK_STATS enabled, and
DMA capability was restored in the IA64 agpgart driver.

The following drivers have been upgraded to new versions:

  cmpci ------ 6.36
  e100 ------- 2.3.30-k1
  e1000 ------ 5.2.20-k1
  ips -------- 6.10.52
  megaraid --- v1.18k
  megaraid2 -- v2.00.9

All Red Hat Enterprise Linux 3 users are advised to upgrade
their kernels to the packages associated with their machine
architectures and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-13" />
        <updated date="2004-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0986.html">CVE-2003-0986</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0001.html">CVE-2004-0001</cve>
                <bugzilla href="http://bugzilla.redhat.com/71514" id="71514">Infinite recursion in SCSI mid layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/77839" id="77839">Assert failure in transaction.c:1224: "!jh->b_committed_data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/101938" id="101938">C write fails for records gt 2 GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102535" id="102535">hang in ptrace for gdb traceback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/104520" id="104520">SMP Kernel hang on shutdown with Intel SRCZCR Raid Controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106004" id="106004">Broadcom tg3 driver duplex won't set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106399" id="106399">SCSI I/O stall problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106502" id="106502">Base driver button not loaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106794" id="106794">LTC4829-RHEL 3 HANGS under heavy stress load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/107960" id="107960">No disk/partition statistics in /proc/partitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108488" id="108488">Millisecond timer resolution on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108648" id="108648">No AGP support on Tyan 2885 K8W</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110895" id="110895">running processes are not listed in /proc, with ps or top</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112365" id="112365">Kernel Panic when running pulse deamon</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017014" comment="kernel-source is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017002" comment="kernel is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017012" comment="kernel-doc is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017018" comment="kernel-hugemem is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017010" comment="kernel-BOOT is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017004" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017008" comment="kernel-unsupported is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040017006" comment="kernel-smp is earlier than 0:2.4.21-9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040023" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:023: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:023-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-023.html" />
          <reference source="CVE" ref_id="CVE-2003-0935" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0935.html" />
    
    <description>The Net-SNMP project includes various Simple Network Management Protocol
(SNMP) tools.

A security issue in Net-SNMP versions before 5.0.9 could allow an existing
user/community to gain access to data in MIB objects that were explicitly
excluded from their view.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0935 to this issue.

Users of Net-SNMP are advised to upgrade to these errata packages
containing Net-SNMP 5.0.9, which is not vulnerable to this issue.  In
addition, Net-SNMP 5.0.9 fixes a number of other minor bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-15" />
        <updated date="2004-01-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0935.html">CVE-2003-0935</cve>
                <bugzilla href="http://bugzilla.redhat.com/109622" id="109622">net-snmp unauthorised access to mibs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023008" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023006" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023004" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040023002" comment="net-snmp is earlier than 0:5.0.9-2.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040031" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:031: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:031-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-031.html" />
          <reference source="CVE" ref_id="CVE-2003-0924" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0924.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps), and others.

A number of temporary file bugs have been found in versions of NetPBM. 
These could make it possible for a local user to overwrite or create files
as a different user who happens to run one of the the vulnerable utilities. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0924 to this issue.

Users are advised to upgrade to the erratum packages, which contain patches
from Debian that correct these bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-19" />
        <updated date="2004-01-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0924.html">CVE-2003-0924</cve>
                <bugzilla href="http://bugzilla.redhat.com/113841" id="113841">CAN-2003-0924 netpbm temporary file vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031002" comment="netpbm is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031004" comment="netpbm-devel is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040031006" comment="netpbm-progs is earlier than 0:9.24-11.30.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040031007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040033" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:033: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-033.html" />
          <reference source="CVE" ref_id="CVE-2004-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0006.html" />
          <reference source="CVE" ref_id="CVE-2004-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0007.html" />
          <reference source="CVE" ref_id="CVE-2004-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0008.html" />
    
    <description>Gaim is an instant messenger client that can handle multiple protocols.

Stefan Esser audited the Gaim source code and found a number of bugs that
have security implications.  Due to the nature of instant messaging many of
these bugs require man-in-the-middle attacks between client and server.
However at least one of the buffer overflows could be exploited by an
attacker sending a carefully-constructed malicious message through a server.

The issues include:

Multiple buffer overflows that affect versions of Gaim 0.75 and earlier. 
1) When parsing cookies in a Yahoo web connection, 2) YMSG protocol
overflows parsing the Yahoo login webpage, 3) a YMSG packet overflow, 4)
flaws in the URL parser, and 5) flaws in HTTP Proxy connect.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0006 to these issues.

A buffer overflow in Gaim 0.74 and earlier in the Extract Info
Field Function used for MSN and YMSG protocol handlers. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0007 to this issue.

An integer overflow in Gaim 0.74 and earlier, when allocating
memory for a directIM packet results in heap overflow.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0008 to this issue.

All users of Gaim should upgrade to these erratum packages, which contain
backported security patches correcting these issues.  

Red Hat would like to thank Steffan Esser for finding and reporting these
issues and Jacques A. Vidrine for providing initial patches.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-19" />
        <updated date="2004-01-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0006.html">CVE-2004-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0007.html">CVE-2004-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0008.html">CVE-2004-0008</cve>
                <bugzilla href="http://bugzilla.redhat.com/113844" id="113844">CAN-2004-0006/7/8 Multiple vulnerabilities in Gaim</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033002" comment="gaim is earlier than 1:0.75-3.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040041" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:041: slocate security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:041-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-041.html" />
          <reference source="CVE" ref_id="CVE-2003-0848" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0848.html" />
          <reference source="CVE" ref_id="CVE-2003-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0056.html" />
    
    <description>Slocate is a security-enhanced version of locate, designed to find files on
a system via a central database.

Patrik Hornik discovered a vulnerability in Slocate versions up to and
including 2.7 where a carefully crafted database could overflow a
heap-based buffer.  A local user could exploit this vulnerability to gain
"slocate" group privileges and then read the entire slocate database.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0848 to this issue.

Users of Slocate should upgrade to these erratum packages, which contain
Slocate version 2.7 with the addition of a patch from Kevin Lindsay that
causes slocate to drop privileges before reading a user-supplied database.

For Red Hat Enterprise Linux 2.1 these packages also fix a buffer overflow
that affected unpatched versions of Slocate prior to 2.7.  This
vulnerability could also allow a local user to gain "slocate" group
privileges.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0056 to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-21" />
        <updated date="2004-01-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0848.html">CVE-2003-0848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0056.html">CVE-2003-0056</cve>
                <bugzilla href="http://bugzilla.redhat.com/114013" id="114013">CAN-2003-0848 slocate buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114016" id="114016">CAN-2003-0056 buffer overflow in slocate</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041002" comment="slocate is earlier than 0:2.7-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040047" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:047: pwlib security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:047-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-047.html" />
          <reference source="CVE" ref_id="CVE-2004-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0097.html" />
    
    <description>PWLib is a cross-platform class library designed to support the OpenH323
project.  OpenH323 provides an implementation of the ITU H.323
teleconferencing protocol, used by packages such as Gnome Meeting.

A test suite for the H.225 protocol (part of the H.323 family) provided by
the NISCC uncovered bugs in PWLib prior to version 1.6.0.  An attacker
could trigger these bugs by sending carefully crafted messages to an
application.  The effects of such an attack can vary depending on the
application, but would usually result in a Denial of Service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0097 to this issue.

Users are advised to upgrade to the erratum packages, which contain
backported security fixes and are not vulnerable to these issues.

Red Hat would like to thank Craig Southeren of the OpenH323 project for
providing the fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-18" />
        <updated date="2004-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0097.html">CVE-2004-0097</cve>
                <bugzilla href="http://bugzilla.redhat.com/114308" id="114308">CAN-2004-0097 PWlib/OpenH323 vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040047002" comment="pwlib is earlier than 0:1.4.7-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040047003" comment="pwlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040047004" comment="pwlib-devel is earlier than 0:1.4.7-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040047005" comment="pwlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040050" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:050: mutt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:050-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-050.html" />
          <reference source="CVE" ref_id="CVE-2004-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0078.html" />
    
    <description>Mutt is a text-mode mail user agent.

A bug was found in the index menu code in versions of mutt.  A remote
attacker could send a carefully crafted mail message that can cause mutt
to segfault and possibly execute arbitrary code as the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0078 to this issue.

It is recommended that all mutt users upgrade to these updated packages,
which contain a backported security patch and are not vulnerable to this issue.

Red Hat would like to thank Niels Heinen for reporting this issue.

Note: mutt-1.2.5.1 in Red Hat Enterprise Linux 2.1 is not vulnerable to
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-11" />
        <updated date="2004-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0078.html">CVE-2004-0078</cve>
                <bugzilla href="http://bugzilla.redhat.com/114448" id="114448">CAN-2004-0078 Mutt can be remotely crashed</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050002" comment="mutt is earlier than 5:1.4.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040050003" comment="mutt is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040053" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:053: sysstat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:053-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-053.html" />
          <reference source="CVE" ref_id="CVE-2004-0107" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0107.html" />
          <reference source="CVE" ref_id="CVE-2004-0108" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0108.html" />
    
    <description>Sysstat is a tool for gathering system statistics. Isag is a utility for
graphically displaying these statistics.

A bug was found in the Red Hat sysstat package post and trigger scripts,
which used insecure temporary file names. A local attacker could overwrite
system files using carefully-crafted symbolic links in the /tmp directory.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0107 to this issue.

While fixing this issue, a flaw was discovered in the isag utility, which
also used insecure temporary file names. A local attacker could overwrite
files that the user running isag has write access to using
carefully-crafted symbolic links in the /tmp directory.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0108 to this issue.

Other issues addressed in this advisory include:

* iostat -x should return all partitions on the system (up to a maximum of
1024)

* sar should handle network device names with more than 8 characters properly

* mpstat should work correctly with more than 7 CPUs as well as generate
correct statistics when accessing individual CPUs.  This issue only
affected Red Hat Enterprise Linux 2.1

* The sysstat package was not built with the proper dependencies;
therefore, it was possible that isag could not be run because the necessary
 tools were not available.  Therefore, isag was split off into its own
subpackage with the required dependencies in place.  This issue only
affects Red Hat Enterprise Linux 2.1.

Users of sysstat and isag should upgrade to these updated packages, which
contain patches to correct these issues.

NOTE: In order to use isag on Red Hat Enterprise Linux 2.1, you must
install the sysstat-isag package after upgrading.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-10" />
        <updated date="2004-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0107.html">CVE-2004-0107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0108.html">CVE-2004-0108</cve>
                <bugzilla href="http://bugzilla.redhat.com/78212" id="78212">sysstat package post scripts, trigger scripts use insecure tmp files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040053002" comment="sysstat is earlier than 0:4.0.7-4.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040053003" comment="sysstat is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040058" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:058: mod_python security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:058-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-058.html" />
          <reference source="CVE" ref_id="CVE-2003-0973" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0973.html" />
          <reference source="CVE" ref_id="CVE-2004-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0096.html" />
    
    <description>mod_python embeds the Python language interpreter within the Apache httpd
server.

A bug has been found in mod_python versions 2.7.10 and earlier that can
lead to a denial of service vulnerability.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0973 to
this issue.

Although Red Hat Enterprise Linux shipped with a version of mod_python that
contains this bug, our testing was unable to trigger the denial of service
vulnerability.  However, mod_python users are advised to upgrade to these
errata packages, which contain a backported patch that corrects this bug.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-26" />
        <updated date="2004-02-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0973.html">CVE-2003-0973</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0096.html">CVE-2004-0096</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058002" comment="mod_python is earlier than 0:3.0.3-3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040061" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:061: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:061-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-061.html" />
          <reference source="CVE" ref_id="CVE-2004-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0083.html" />
          <reference source="CVE" ref_id="CVE-2004-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0084.html" />
          <reference source="CVE" ref_id="CVE-2004-0106" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0106.html" />
    
    <description>XFree86 is an implementation of the X Window System, providing the core
graphical user interface and video drivers. 

iDefense discovered two buffer overflows in the parsing of the 'font.alias'
file.  A local attacker could exploit this vulnerability by creating a
carefully-crafted file and gaining root privileges.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0083 and CAN-2004-0084 to these issues.

Additionally David Dawes discovered additional flaws in reading font files.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0106 to these issues.

All users of XFree86 are advised to upgrade to these erratum packages,
which contain a backported fix and are not vulnerable to these issues.

Red Hat would like to thank David Dawes from XFree86 for the patches and
notification of these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-16" />
        <updated date="2004-02-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0083.html">CVE-2004-0083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0084.html">CVE-2004-0084</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0106.html">CVE-2004-0106</cve>
                <bugzilla href="http://bugzilla.redhat.com/114902" id="114902">CAN-2004-0083 XFree86 font.alias overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061052" comment="XFree86-xdm is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061022" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061036" comment="XFree86-libs-data is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061026" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061014" comment="XFree86-doc is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061010" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061002" comment="XFree86 is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061046" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061038" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061034" comment="XFree86-libs is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061054" comment="XFree86-xfs is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061006" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061056" comment="XFree86-Xnest is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061042" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061020" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061030" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061024" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061040" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061004" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061018" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061016" comment="XFree86-font-utils is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061008" comment="XFree86-base-fonts is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061058" comment="XFree86-Xvfb is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061048" comment="XFree86-twm is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061044" comment="XFree86-tools is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061050" comment="XFree86-xauth is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040061012" comment="XFree86-devel is earlier than 0:4.3.0-55.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040064" version="506" class="patch">
      <metadata>
        <title>RHSA-2004:064: samba security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:064-05" ref_url="https://rhn.redhat.com/errata/RHSA-2004-064.html" />
          <reference source="CVE" ref_id="CVE-2004-0082" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0082.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

The Samba team discovered an issue that affects version 3.0.0 and 3.0.1 of
Samba.  If an account for a user is created, but marked as disabled using
the mksmbpasswd script, it is possible for Samba to overwrite the user's
password with the contents of an uninitialized buffer.  This might lead to
a disabled account becoming enabled with a password that could be guessed
by an attacker.

Although this is likely to be a low risk issue for most Samba users, we
have provided updated packages, which contain a backported patch correcting
this issue.

Red Hat would like to thank the Samba team for reporting this issue and
providing us with a patch.

Note: Due to a packaging error in samba-3.0.0-14.3E, the winbind daemon is
not automatically restarted when the Samba package is upgraded.  After
up2date has installed the samba-3.0.2-4.3E packages, you must run
"/sbin/service winbind condrestart" as root to restart the winbind daemon.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-21" />
        <updated date="2004-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0082.html">CVE-2004-0082</cve>
                <bugzilla href="http://bugzilla.redhat.com/114995" id="114995">CAN-2004-0082 mksmbpasswd vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064004" comment="samba-client is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064006" comment="samba-common is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064002" comment="samba is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040064008" comment="samba-swat is earlier than 0:3.0.2-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040066" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:066: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-066.html" />
          <reference source="CVE" ref_id="CVE-2004-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0077.html" />
    
    <description>The Linux kernel handles the basic functions of the operating
system.

Paul Starzetz discovered a flaw in return value checking in mremap() in the
Linux kernel versions 2.4.24 and previous that may allow a local attacker
to gain root privileges.  No exploit is currently available; however this
issue is exploitable. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0077 to this issue.

All users are advised to upgrade to these errata packages, which contain
backported security patches that correct these issues.   

Red Hat would like to thank Paul Starzetz from ISEC for reporting this issue.

For the IBM S/390 and IBM eServer zSeries architectures, the upstream
version of the s390utils package (which fixes a bug in the zipl
bootloader) is also included.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-20" />
        <updated date="2004-02-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0077.html">CVE-2004-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/112891" id="112891">OOM killer strikes with lots of free swap space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113517" id="113517">RHEL 3.0 smp hang using prctl( PR_SET_PDEATHSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115820" id="115820">CAN-2004-0077 Linux kernel do_mremap VMA limit local privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066014" comment="kernel-source is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066002" comment="kernel is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066012" comment="kernel-doc is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066016" comment="kernel-hugemem is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066010" comment="kernel-BOOT is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066008" comment="kernel-unsupported is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066004" comment="kernel-smp is earlier than 0:2.4.21-9.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040066020" comment="s390utils is earlier than 2:1.2.4-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040066021" comment="s390utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040072" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:072: nfs-utils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:072-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-072.html" />
          <reference source="CVE" ref_id="CVE-2004-0154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0154.html" />
    
    <description>The nfs-utils package contains the rpc.mountd program, which implements the
NFS mount protocol.

A flaw was discovered in versions of rpc.mountd in nfs-utils versions after
1.0.3 and prior to 1.0.6.  When mounting a directory, rpc.mountd could
crash if the reverse lookup of the client in DNS failed to match the
forward lookup.  An attacker who has the ability to mount remote
directories from a server could make use of this flaw to cause a denial of
service by making rpc.mountd crash.

Users are advised to upgrade to these updated packages, which contain
nfs-utils 1.0.6 and is not vulnerable to this issue.

NOTE: Red Hat Enterprise Linux 2.1 includes a version of rpc.mountd that is
not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-11" />
        <updated date="2004-03-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0154.html">CVE-2004-0154</cve>
                <bugzilla href="http://bugzilla.redhat.com/114535" id="114535">rpc.mountd killed by remote mount request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072002" comment="nfs-utils is earlier than 0:1.0.6-7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072003" comment="nfs-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040084" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:084: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:084-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-084.html" />
          <reference source="CVE" ref_id="CVE-2004-0113" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0113.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

A memory leak in mod_ssl in the Apache HTTP Server prior to version 2.0.49
allows a remote denial of service attack against an SSL-enabled server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0113 to this issue.

This update also includes various bug fixes, including:

- Improvements to the mod_expires, mod_dav, mod_ssl, and mod_proxy modules

- A fix for a bug causing core dumps during configuration parsing on the
IA64 platform

- An updated version of mod_include fixing several edge cases in the SSI parser

Additionally, the mod_logio module is now included.

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-23" />
        <updated date="2004-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0113.html">CVE-2004-0113</cve>
                <bugzilla href="http://bugzilla.redhat.com/112771" id="112771">Invalid paths in config_vars.mk crash build of mod_jk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113929" id="113929">mod_expires headers not set when used in conjunction with mod_proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113934" id="113934">SRPMS: test for MMN version it too fragile</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115328" id="115328">Satisfy keyword in httpd.conf causes apache to segfault on load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115379" id="115379">pcre conflict between httpd and php</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117280" id="117280">CAN-2004-0113 mod_ssl Denial of Service attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084004" comment="httpd-devel is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084006" comment="mod_ssl is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040084002" comment="httpd is earlier than 0:2.0.46-32.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040090" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:090: libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-090.html" />
          <reference source="CVE" ref_id="CVE-2004-0110" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0110.html" />
    
    <description>libxml2 is a library for manipulating XML files.

Yuuichi Teranishi discovered a flaw in libxml2 versions prior to 2.6.6. 
When fetching a remote resource via FTP or HTTP, libxml2 uses special
parsing routines.  These routines can overflow a buffer if passed a very
long URL.  If an attacker is able to find an application using libxml2 that
parses remote resources and allows them to influence the URL, then this
flaw could be used to execute arbitrary code.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0110
to this issue.

All users are advised to upgrade to these updated packages, which contain a
backported fix and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-02-26" />
        <updated date="2004-02-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0110.html">CVE-2004-0110</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090002" comment="libxml2 is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090003" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090004" comment="libxml2-devel is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090005" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040090006" comment="libxml2-python is earlier than 0:2.5.10-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090007" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040103" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:103: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-103.html" />
          <reference source="CVE" ref_id="CVE-2004-0111" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0111.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the 
GNOME GUI desktop environment.  

Thomas Kristensen discovered a bitmap file that would cause versions of
gdk-pixbuf prior to 0.20 to crash.  To exploit this flaw, an attacker would
need to get a victim to open a carefully-crafted BMP file in an application
that used gdk-pixbuf.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0111 to this issue.

Users are advised to upgrade to these updated packages containing
gdk-pixbuf version 0.22, which is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-10" />
        <updated date="2004-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0111.html">CVE-2004-0111</cve>
                <bugzilla href="http://bugzilla.redhat.com/116918" id="116918">CAN-2004-0111 gdk-pixbuf can crash with malicious BMP file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040103002" comment="gdk-pixbuf is earlier than 1:0.22.0-6.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040110" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:110: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:110-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-110.html" />
          <reference source="CVE" ref_id="CVE-2003-0564" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0564.html" />
          <reference source="CVE" ref_id="CVE-2003-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0594.html" />
          <reference source="CVE" ref_id="CVE-2004-0191" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0191.html" />
    
    <description>Mozilla is a Web browser and mail reader, designed for standards
compliance, performance and portability.  Network Security Services (NSS)
is a set of libraries designed to support cross-platform development of
security-enabled server applications. 

NISCC testing of implementations of the S/MIME protocol uncovered a number
of bugs in NSS versions prior to 3.9.   The parsing of unexpected ASN.1
constructs within S/MIME data could cause Mozilla to crash or consume large
amounts of memory.  A remote attacker could potentially trigger these bugs
by sending a carefully-crafted S/MIME message to a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0564 to this issue. 

Andreas Sandblad discovered a cross-site scripting issue that affects
various versions of Mozilla.  When linking to a new page it is still
possible to interact with the old page before the new page has been
successfully loaded. Any Javascript events will be invoked in the context
of the new page, making cross-site scripting possible if the different
pages belong to different domains.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0191 to
this issue. 

Flaws have been found in the cookie path handling between a number of Web
browsers and servers. The HTTP cookie standard allows a Web server
supplying a cookie to a client to specify a subset of URLs on the origin
server to which the cookie applies. Web servers such as Apache do not
filter returned cookies and assume that the client will only send back
cookies for requests that fall within the server-supplied subset of URLs.
However, by supplying URLs that use path traversal (/../) and character
encoding, it is possible to fool many browsers into sending a cookie to a
path outside of the originally-specified subset.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0594 to this issue. 

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.4.2 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-02" />
        <updated date="2004-04-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0564.html">CVE-2003-0564</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0594.html">CVE-2003-0594</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0191.html">CVE-2004-0191</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110018" comment="mozilla-js-debugger is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110014" comment="mozilla-mail is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110016" comment="mozilla-chat is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110010" comment="mozilla-nss-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110002" comment="mozilla is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110020" comment="mozilla-dom-inspector is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110006" comment="mozilla-nspr-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110004" comment="mozilla-nspr is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110012" comment="mozilla-devel is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040110008" comment="mozilla-nss is earlier than 37:1.4.2-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040120" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:120: openssl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:120-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-120.html" />
          <reference source="CVE" ref_id="CVE-2004-0079" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0079.html" />
          <reference source="CVE" ref_id="CVE-2004-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0081.html" />
          <reference source="CVE" ref_id="CVE-2004-0112" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0112.html" />
    
    <description>The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),
Transport Layer Security (TLS v1) protocols, and serves as a full-strength
general purpose cryptography library.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a null-pointer assignment in the do_change_cipher_spec() function
in OpenSSL 0.9.6c-0.9.6k and 0.9.7a-0.9.7c.  A remote attacker could
perform a carefully crafted SSL/TLS handshake against a server that uses
the OpenSSL library in such a way as to cause OpenSSL to crash. Depending
on the application this could lead to a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0079 to this issue.

Stephen Henson discovered a flaw in SSL/TLS handshaking code when using
Kerberos ciphersuites in OpenSSL 0.9.7a-0.9.7c.  A remote attacker could
perform a carefully crafted SSL/TLS handshake against a server configured
to use Kerberos ciphersuites in such a way as to cause OpenSSL to crash. 
Most applications have no ability to use Kerberos ciphersuites and will
therefore be unaffected by this issue.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0112 to
this issue.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a bug in older versions of OpenSSL 0.9.6 prior to 0.9.6d that may
lead to a denial of service attack (infinite loop).  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0081 to this issue.  This issue affects only the OpenSSL
compatibility packages shipped with Red Hat Enterprise Linux 3.

These updated packages contain patches provided by the OpenSSL group that
protect against these issues.

Additionally, the version of libica included in the OpenSSL packages has
been updated to 1.3.5. This only affects IBM s390 and IBM eServer zSeries
customers and is required for the latest openCryptoki packages.

NOTE: Because server applications are affected by this issue, users are
advised to either restart all services that use OpenSSL functionality or
restart their systems after installing these updates.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-21" />
        <updated date="2004-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0079.html">CVE-2004-0079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0081.html">CVE-2004-0081</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0112.html">CVE-2004-0112</cve>
                <bugzilla href="http://bugzilla.redhat.com/117770" id="117770">CAN-2004-0079/0081/0112 Flaws in OpenSSL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120002" comment="openssl is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120006" comment="openssl-perl is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120004" comment="openssl-devel is earlier than 0:0.9.7a-33.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040120008" comment="openssl096b is earlier than 0:0.9.6b-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040120009" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040133" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:133: squid security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:133-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-133.html" />
          <reference source="CVE" ref_id="CVE-2004-0189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0189.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A bug was found in the processing of %-encoded characters in a URL in
versions of Squid 2.5.STABLE4 and earlier.  If a Squid configuration uses
Access Control Lists (ACLs), a remote attacker could create URLs that would
not be correctly tested against Squid's ACLs, potentially allowing clients
to access prohibited URLs.

Users of Squid should update to these erratum packages which are not
vulnerable to this issue.

In addition, these packages contain a new Access Control type, "urllogin",
which can be used to protect vulnerable Microsoft Internet Explorer clients
from accessing URLs that contain login information.  Such URLs are often
used by fraudsters to trick web users into revealing valuable personal data.

Note that the default Squid configuration does not make use of this new
access control type.  You must explicitly configure Squid with ACLs that
use this new type, in accordance with your own site policies.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0189.html">CVE-2004-0189</cve>
                <bugzilla href="http://bugzilla.redhat.com/118032" id="118032">CAN-2004-0189 Squid ACL bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133002" comment="squid is earlier than 7:2.5.STABLE3-5.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040136" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:136: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-136.html" />
          <reference source="CVE" ref_id="CVE-2004-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0176.html" />
          <reference source="CVE" ref_id="CVE-2004-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0365.html" />
          <reference source="CVE" ref_id="CVE-2004-0367" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0367.html" />
          <reference source="CVE" ref_id="CVE-2004-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1761.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

Stefan Esser reported that Ethereal versions 0.10.1 and earlier contain
stack overflows in the IGRP, PGM, Metflow, ISUP, TCAP, or IGAP dissectors.
 On a system where Ethereal is being run a remote attacker could send
malicious packets that could cause Ethereal to crash or execute arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0176 to this issue.

Jonathan Heussser discovered that a carefully-crafted RADIUS packet could
cause a crash.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0365 to this issue.

Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of
service (crash) via a zero-length Presentation protocol selector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0367 to this issue.

Users of Ethereal should upgrade to these updated packages, which contain
a version of Ethereal that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-03-30" />
        <updated date="2004-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0176.html">CVE-2004-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0365.html">CVE-2004-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0367.html">CVE-2004-0367</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1761.html">CVE-2004-1761</cve>
                <bugzilla href="http://bugzilla.redhat.com/118143" id="118143">CAN-2004-0176 Ethereal  dissector overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040136004" comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040136002" comment="ethereal is earlier than 0:0.10.3-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040153" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:153: cvs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:153-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-153.html" />
          <reference source="CVE" ref_id="CVE-2004-0180" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0180.html" />
          <reference source="CVE" ref_id="CVE-2004-0405" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0405.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.  

Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can
create files with absolute pathnames.  An attacker could create a fake
malicious CVS server that would cause arbitrary files to be created or
overwritten when a victim connects to it.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0180 to
this issue.

Derek Price discovered a vulnerability whereby a CVS pserver could be
abused by a malicious client to view the contents of certain files outside
of the CVS root directory using relative pathnames containing "../". The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0405 to this issue.

Users of CVS are advised to upgrade to these erratum packages, which
contain a patch correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0180.html">CVE-2004-0180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0405.html">CVE-2004-0405</cve>
                <bugzilla href="http://bugzilla.redhat.com/118719" id="118719">CAN-2004-0180 Malicious CVS server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040153002" comment="cvs is earlier than 0:1.11.2-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040160" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:160: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-160.html" />
          <reference source="CVE" ref_id="CVE-2004-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0179.html" />
    
    <description>OpenOffice.org is an Open Source, community-developed, multi-platform
office productivity suite.  OpenOffice internally uses inbuilt code
from neon, an HTTP and WebDAV client library.

Versions of the neon client library up to and including 0.24.4 have been
found to contain a number of format string bugs.  An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using OpenOffice.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0179 to this issue.

Users of OpenOffice are advised to upgrade to these updated packages, which
contain a patch correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14" />
        <updated date="2004-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0179.html">CVE-2004-0179</cve>
                <bugzilla href="http://bugzilla.redhat.com/119830" id="119830">CAN-2004-0179 neon format string vulnerability affects openoffice</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160006" comment="openoffice.org-i18n is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160002" comment="openoffice.org is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040160004" comment="openoffice.org-libs is earlier than 0:1.1.0-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040165" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:165: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-165.html" />
          <reference source="CVE" ref_id="CVE-2004-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0155.html" />
          <reference source="CVE" ref_id="CVE-2004-0164" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0164.html" />
          <reference source="CVE" ref_id="CVE-2004-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0403.html" />
    
    <description>IPSEC uses strong cryptography to provide both authentication and
encryption services.

With versions of ipsec-tools prior to 0.2.3, it was possible for an
attacker to cause unauthorized deletion of SA (Security Associations.)
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0164 to this issue.

With versions of ipsec-tools prior to 0.2.5, the RSA signature on x.509
certificates was not properly verified when using certificate based
authentication.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0155 to this issue.

When ipsec-tools receives an ISAKMP header, it will attempt to allocate
sufficient memory for the entire ISAKMP message according to the header's
length field. If an attacker crafts an ISAKMP header with a extremely large
value in the length field, racoon may exceed operating system resource
limits and be terminated, resulting in a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0403 to this issue.

User of IPSEC should upgrade to this updated package, which contains
ipsec-tools version 0.25 along with a security patch for CAN-2004-0403
which resolves all these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-11" />
        <updated date="2004-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0155.html">CVE-2004-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0164.html">CVE-2004-0164</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0403.html">CVE-2004-0403</cve>
                <bugzilla href="http://bugzilla.redhat.com/120253" id="120253">CAN-2004-0155/CAN-2004-0164/CAN-2004-0403 IPSEC vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165002" comment="ipsec-tools is earlier than 0:0.2.5-0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040174" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:174: utempter security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:174-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-174.html" />
          <reference source="CVE" ref_id="CVE-2004-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0233.html" />
    
    <description>Utempter is a utility that allows terminal applications such as xterm and
screen to update utmp and wtmp without requiring root privileges.

Steve Grubb discovered a flaw in Utempter which allowed device names
containing directory traversal sequences such as '/../'.  In combination
with an application that trusts the utmp or wtmp files, this could allow a
local attacker the ability to overwrite privileged files using a symlink.

Users should upgrade to this new version of utempter, which fixes this
vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0233.html">CVE-2004-0233</cve>
                <bugzilla href="http://bugzilla.redhat.com/121332" id="121332">CAN-2004-0233 utempter directory traversal symlink attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040174002" comment="utempter is earlier than 0:0.5.5-1.3EL.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040174003" comment="utempter is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040178" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:178: lha security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:178-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-178.html" />
          <reference source="CVE" ref_id="CVE-2004-0234" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0234.html" />
          <reference source="CVE" ref_id="CVE-2004-0235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0235.html" />
    
    <description>LHA is an archiving and compression utility for LHarc format archives.

Ulf Harnhammar discovered two stack buffer overflows and two directory
traversal flaws in LHA.  An attacker could exploit the buffer overflows by
creating a carefully crafted LHA archive in such a way that arbitrary code
would be executed when the archive is tested or extracted by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0234 to this issue.  An attacker could exploit
the directory traversal issues to create files as the victim outside of the
expected directory.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0235 to this issue.

Users of LHA should update to this updated package which contains
backported patches not vulnerable to these issues.

Red Hat would like to thank Ulf Harnhammar for disclosing and providing
test cases and patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0234.html">CVE-2004-0234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0235.html">CVE-2004-0235</cve>
                <bugzilla href="http://bugzilla.redhat.com/121417" id="121417">CAN-2004-0234/0235 lha security flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178002" comment="lha is earlier than 0:1.14i-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178003" comment="lha is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040180" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:180: libpng security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-180.html" />
          <reference source="CVE" ref_id="CVE-2004-0421" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0421.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.  

Steve Grubb discovered a out of bounds memory access flaw in libpng.  An
attacker could carefully craft a PNG file in such a way that it would cause
an application linked to libpng to crash when opened by a victim.  This
issue may not be used to execute arbitrary code.  

Users are advised to upgrade to these updated packages that contain a
backported security fix not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0421.html">CVE-2004-0421</cve>
                <bugzilla href="http://bugzilla.redhat.com/121229" id="121229">CAN-2004-0421 libpng can access out of bounds memory</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180002" comment="libpng is earlier than 2:1.2.2-21" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180004" comment="libpng-devel is earlier than 2:1.2.2-21" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180008" comment="libpng10-devel is earlier than 0:1.0.13-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040180006" comment="libpng10 is earlier than 0:1.0.13-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040183" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:183: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:183-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-183.html" />
          <reference source="CVE" ref_id="CVE-2004-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0109.html" />
          <reference source="CVE" ref_id="CVE-2004-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0424.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

iSEC Security Research discovered a flaw in the ip_setsockopt() function
code of the Linux kernel versions 2.4.22 to 2.4.25 inclusive.  This flaw 
also affects the 2.4.21 kernel in Red Hat Enterprise Linux 3 which
contained a backported version of the affected code.  A local user could
use this flaw to gain root privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0424 to
this issue.

iDefense reported a buffer overflow flaw in the ISO9660 filesystem code.
An attacker could create a malicious filesystem in such a way that root
privileges may be obtained if the filesystem is mounted. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0109 to this issue.

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-22" />
        <updated date="2004-04-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0109.html">CVE-2004-0109</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0424.html">CVE-2004-0424</cve>
                <bugzilla href="http://bugzilla.redhat.com/120028" id="120028">CAN-2004-0109 kernel iso9660 buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121314" id="121314">CAN-2004-0424 Linux kernel setsockopt MCAST_MSFILTER integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183006" comment="kernel-source is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183002" comment="kernel is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183008" comment="kernel-doc is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183018" comment="kernel-hugemem is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183010" comment="kernel-BOOT is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183004" comment="kernel-unsupported is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040183014" comment="kernel-smp is earlier than 0:2.4.21-9.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040188" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:188: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 2 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:188-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-188.html" />
          <reference source="CVE" ref_id="CVE-2003-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0461.html" />
          <reference source="CVE" ref_id="CVE-2003-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0465.html" />
          <reference source="CVE" ref_id="CVE-2003-0984" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0984.html" />
          <reference source="CVE" ref_id="CVE-2003-1040" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-1040.html" />
          <reference source="CVE" ref_id="CVE-2004-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0003.html" />
          <reference source="CVE" ref_id="CVE-2004-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0010.html" />
    
    <description>The Linux kernel handles the basic functions of the
operating system.

This is the second regular kernel update to Red Hat
Enterprise Linux version 3.  It contains several minor
security fixes, many bug fixes, device driver updates,
new hardware support, and the introduction of Linux
Syscall Auditing support.

There were bug fixes in many different parts of the kernel,
the bulk of which addressed unusual situations such as error
handling, race conditions, and resource starvation.  The
combined effect of the approximately 140 fixes is a strong
improvement in the reliability and durability of Red Hat
Enterprise Linux.  Some of the key areas affected are disk
drivers, network drivers, USB support, x86_64 and ppc64
platform support, ia64 32-bit emulation layer enablers,
and the VM, NFS, IPv6, and SCSI subsystems.

A significant change in the SCSI subsystem (the disabling
of the scsi-affine-queue patch) should significantly improve
SCSI disk driver performance in many scenarios.  There were
10 Bugzillas against SCSI performance problems addressed
by this change.

The following drivers have been upgraded to new versions:

  bonding ---- 2.4.1
  cciss ------ 2.4.50.RH1
  e1000 ------ 5.2.30.1-k1
  fusion ----- 2.05.11.03
  ipr -------- 1.0.3
  ips -------- 6.11.07
  megaraid2 -- 2.10.1.1
  qla2x00 ---- 6.07.02-RH1
  tg3 -------- 3.1
  z90crypt --- 1.1.4

This update introduces support for the new Intel EM64T
processor.  A new "ia32e" architecture has been created to
support booting on platforms based on either the original
AMD Opteron CPU or the new Intel EM64T CPU.  The existing
"x86_64" architecture has remained optimized for Opteron
systems.  Kernels for both types of systems are built from
the same x86_64-architecture sources and share a common
kernel source RPM (kernel-source-2.4.21-15.EL.x86_64.rpm).

Other highlights in this update include a major upgrade to
the SATA infrastructure, addition of IBM JS20 Power Blade
support, and creation of an optional IBM eServer zSeries
On-Demand Timer facility for reducing idle CPU overhead.

The following security issues were addressed in this update:

A minor flaw was found where /proc/tty/driver/serial reveals
the exact character counts for serial links.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0461 to this issue.

The kernel strncpy() function in Linux 2.4 and 2.5 does not
pad the target buffer with null bytes on architectures other
than x86, as opposed to the expected libc behavior, which
could lead to information leaks.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0465 to this issue.

A minor data leak was found in two real time clock drivers
(for /dev/rtc).  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name
CAN-2003-0984 to this issue.

A flaw in the R128 Direct Render Infrastructure (dri) driver
could allow local privilege escalation.  This driver is part
of the kernel-unsupported package.  The Common Vulnera-
bilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0003 to this issue.

A flaw in ncp_lookup() in ncpfs could allow local privilege
escalation.  The ncpfs module allows a system to mount
volumes of NetWare servers or print to NetWare printers and
is in the kernel-unsupported package.  The Common Vulnera-
bilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0010 to this issue.

(Note that the kernel-unsupported package contains drivers
and other modules that are unsupported and therefore might
contain security problems that have not been addressed.)

All Red Hat Enterprise Linux 3 users are advised to upgrade
their kernels to the packages associated with their machine
architectures and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-11" />
        <updated date="2004-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0461.html">CVE-2003-0461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0465.html">CVE-2003-0465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0984.html">CVE-2003-0984</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-1040.html">CVE-2003-1040</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0003.html">CVE-2004-0003</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0010.html">CVE-2004-0010</cve>
                <bugzilla href="http://bugzilla.redhat.com/102194" id="102194">Disk READ performance worse compared with 2.4.20-18.9smp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/104633" id="104633">The synchronous write() system call of RHEL3.0 is slower than that of RHEL2.1.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106503" id="106503">ia64 kernel stops allocating memory too early when overcommit_memory set to strict</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106584" id="106584">'cp -p' returns error when destination is an nfs directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/106969" id="106969">Random stall during boot-up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108958" id="108958">MINSIGSTKSZ mismatch between ia32 and ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109618" id="109618">3ware raid extremely low throughput</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109843" id="109843">Typo in module parameter  of scsi_mod module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/109914" id="109914">PATCH: LTC5351-Large external array causes SIGILL in 32-bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110170" id="110170">[PATCH] LTC5381- rhel 3 will need to pick up the cyclone-lpj-fix patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/110999" id="110999">clock is running to fast on IBM x445</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111250" id="111250">tg3 driver fails to autonegotiate correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111264" id="111264">ada compiler crashes on even hello-world</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111287" id="111287">[PATCH] alternate signal stack bug corrupts RNaT bits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111629" id="111629">ACL over NFS problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111681" id="111681">Invalid ICMP type 11 messages echo'd to console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111768" id="111768">/proc/pid/statm can return negative values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111903" id="111903">[PATCH] oops in IUCV code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/111911" id="111911">avoid hang during initialization on I/O errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112190" id="112190">Duplicate get_partition_list bug to track Bugzilla 111342 in Taroon -</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112359" id="112359">RHEL 3.0 using v6.06.00b11 driver attached to McData switch doesn't log in or scan devices successfully.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112449" id="112449">(TG3) driver doesn't work properly with bcm5700 nic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112584" id="112584">reservation error code, corrupts request queue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112764" id="112764">RHEL3 kernel not preventing or recovering from fork bomb when ulimit used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112826" id="112826">LTC5732 - MMIO alignment error when inserting the olympic TR module.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113071" id="113071">[PATCH] RHEL3 ia64: 32 bit applications don't dump core properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113072" id="113072">[PATCH] RHEL3/ia64: strace -f on multithreaded 32 bit applications doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113099" id="113099">CAN-2003-0461 /proc reveals char count</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113100" id="113100">CAN-2003-0465 kernel strncpy padding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113103" id="113103">CAN-2003-0984 minor /dev/rtc leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113171" id="113171">lousy read performance on megaraid with 2.4.21-4.0.2.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113341" id="113341">netdump - various race conditions that lead to hangs in panic()/die()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113413" id="113413">too many ipv6 aliases cause kernel oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113604" id="113604">CAN-2004-0003 r128 DRI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113809" id="113809">depmod is not run for kernel-2.4.21-9.EL from Quaterly Update #1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113890" id="113890">[PATCH] Excutable compiled on x86 can cause kernel seg fault on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114052" id="114052">Raw device performance poor under WS 3 Dreamworks IT#29689</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114135" id="114135">LSI Megaraid(2) performance subpar in RHEL3, using RHEL3 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114553" id="114553">Bad performance with Q1 update kernel (-9EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114560" id="114560">zfcp updates for RHEL3 U2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114773" id="114773">Panic in elf_core_copy_regs() core dumping ia32 binary</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114869" id="114869">date returns future year of 586562</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114940" id="114940">RHEL 3.0 default QLogic driver v6.06.00b11 spews sg_low_free and QUEUE FULL messages at load time.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114942" id="114942">Running I/O on RHEL 3.0 and using the v6.06.00b11 driver, the driver ran out of memory and began arbitrarily killing processes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115273" id="115273">bad disk I/O performance with the 2.4.21-4.ELsmp kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115438" id="115438">strange load - kswapd/IO ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115823" id="115823">CAN-2004-0010 ncpfs hole (unsupported)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116916" id="116916">tg3 driver doesn't support bonding driver's ALB mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117741" id="117741">P4 2.8ghz HT, Using RHEL WS 3.0 Update 1, latest SMP Kernel, see only 1 CPU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117941" id="117941">frequent kernel panics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118397" id="118397">system needlessly thrashing swap partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118556" id="118556">MTRRs not initialized correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118647" id="118647">kswapd in state R and D load constant at 1+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118882" id="118882">Machine doesn't boot SMP Kernel after installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118885" id="118885">[PATCH] kernel panics when removing expired IPsec SAs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119174" id="119174">/proc/cpuinfo vendor_id is wrong. shows $</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119545" id="119545">kernel module binfmt_misc missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119903" id="119903">nfs peformance very bad on EL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120341" id="120341">Runaway processes with USB console on Blade Center</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122077" id="122077">servers freeze (only respond to ping and sysrq) periodically</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188006" comment="kernel-source is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188002" comment="kernel is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188008" comment="kernel-doc is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188014" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188016" comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188018" comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188004" comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040188012" comment="kernel-smp is earlier than 0:2.4.21-15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040190" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:190: cvs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:190-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-190.html" />
          <reference source="CVE" ref_id="CVE-2004-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0396.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.

Stefan Esser discovered a flaw in cvs where malformed "Entry"
lines could cause a heap overflow.  An attacker who has access to a CVS
server could use this flaw to execute arbitrary code under the UID which
the CVS server is executing.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0396 to this issue.

Users of CVS are advised to upgrade to this updated package, which contains
a backported patch correcting this issue.

Red Hat would like to thank Stefan Esser for notifying us of this issue and
Derek Price for providing an updated patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0396.html">CVE-2004-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/122384" id="122384">CAN-2004-0396 CVS pserver heap overflow via Entry/Is-modified/Unchanged</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040190002" comment="cvs is earlier than 0:1.11.2-22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040192" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:192: rsync security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:192-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-192.html" />
          <reference source="CVE" ref_id="CVE-2004-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0426.html" />
    
    <description>Rsync is a program for synchronizing files over a network.

Rsync before 2.6.1 does not properly sanitize paths when running a
read/write daemon without using chroot.  This could allow a remote attacker
to write files outside of the module's "path", depending on the privileges
assigned to the rsync daemon.  Users not running an rsync daemon, running a
read-only daemon, or running a chrooted daemon are not affected by this
issue.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0426 to this issue.

Users of Rsync are advised to upgrade to this updated package, which
contains a backported patch and is not affected by this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-19" />
        <updated date="2004-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0426.html">CVE-2004-0426</cve>
                <bugzilla href="http://bugzilla.redhat.com/122511" id="122511">CAN-2004-0426 rsync directory traversal</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040192002" comment="rsync is earlier than 0:2.5.7-4.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040219" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:219: tcpdump security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-219.html" />
          <reference source="CVE" ref_id="CVE-2004-0183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0183.html" />
          <reference source="CVE" ref_id="CVE-2004-0184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0184.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic. 

Tcpdump v3.8.1 and earlier versions contained multiple flaws in the
packet display functions for the ISAKMP protocol.  Upon receiving
specially crafted ISAKMP packets, TCPDUMP would try to read beyond
the end of the packet capture buffer and subsequently crash.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-05-26" />
        <updated date="2004-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0183.html">CVE-2004-0183</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0184.html">CVE-2004-0184</cve>
                <bugzilla href="http://bugzilla.redhat.com/120022" id="120022">CAN-2004-0183/0184 tcpdump ISAKMP crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123030" id="123030">CAN-2004-0183/0184 tcpdump ISAKMP crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219004" comment="libpcap is earlier than 14:0.7.2-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219002" comment="tcpdump is earlier than 14:3.7.2-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040219006" comment="arpwatch is earlier than 14:2.1a11-7.E3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040219007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040233" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:233: cvs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:233-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-233.html" />
          <reference source="CVE" ref_id="CVE-2004-0414" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0414.html" />
          <reference source="CVE" ref_id="CVE-2004-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0416.html" />
          <reference source="CVE" ref_id="CVE-2004-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0417.html" />
          <reference source="CVE" ref_id="CVE-2004-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0418.html" />
          <reference source="CVE" ref_id="CVE-2004-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0778.html" />
    
    <description>CVS is a version control system frequently used to manage source code
repositories.

While investigating a previously fixed vulnerability, Derek Price
discovered a flaw relating to malformed "Entry" lines which lead to a
missing NULL terminator.   The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0414 to this issue.

Stefan Esser and Sebastian Krahmer conducted an audit of CVS and fixed a
number of issues that may have had security consequences.

Among the issues deemed likely to be exploitable were: 

-- a double-free relating to the error_prog_name string (CAN-2004-0416)
-- an argument integer overflow (CAN-2004-0417)
-- out-of-bounds writes in serv_notify (CAN-2004-0418).

An attacker who has access to a CVS server may be able to execute arbitrary
code under the UID on which the CVS server is executing. 

Users of CVS are advised to upgrade to this updated package, which contains
backported patches correcting these issues.

Red Hat would like to thank Stefan Esser, Sebastian Krahmer, and Derek
Price for auditing, disclosing, and providing patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0414.html">CVE-2004-0414</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0416.html">CVE-2004-0416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0417.html">CVE-2004-0417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0418.html">CVE-2004-0418</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0778.html">CVE-2004-0778</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040233002" comment="cvs is earlier than 0:1.11.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040234" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:234: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:234-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-234.html" />
          <reference source="CVE" ref_id="CVE-2004-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0504.html" />
          <reference source="CVE" ref_id="CVE-2004-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0505.html" />
          <reference source="CVE" ref_id="CVE-2004-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0506.html" />
          <reference source="CVE" ref_id="CVE-2004-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0507.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

The MMSE dissector in Ethereal releases 0.10.1 through 0.10.3 contained a
buffer overflow flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0507 to this issue.

In addition, other flaws in Ethereal prior to 0.10.4 were found that could
cause it to crash in response to carefully crafted SIP (CAN-2004-0504), AIM
(CAN-2004-0505), or SPNEGO (CAN-2004-0506) packets.

Users of Ethereal should upgrade to these updated packages, which contain
backported security patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0504.html">CVE-2004-0504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0505.html">CVE-2004-0505</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0506.html">CVE-2004-0506</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0507.html">CVE-2004-0507</cve>
                <bugzilla href="http://bugzilla.redhat.com/124534" id="124534">CAN-2004-0504/5/6/7 Ethereal 0.10.4 contains security fixes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040234004" comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040234002" comment="ethereal is earlier than 0:0.10.3-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040236" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:236: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:236-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-236.html" />
          <reference source="CVE" ref_id="CVE-2004-0523" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0523.html" />
    
    <description>Kerberos is a network authentication system.

Bugs have been fixed in the krb5_aname_to_localname library function.
Specifically, buffer overflows were possible for all Kerberos versions up
to and including 1.3.3. The krb5_aname_to_localname function translates a
Kerberos principal name to a local account name, typically a UNIX username.
This function is frequently used when performing authorization checks.

If configured with mappings from particular Kerberos principals to
particular UNIX user names, certain functions called by
krb5_aname_to_localname will not properly check the lengths of buffers
used to store portions of the principal name.  If configured to map
principals to user names using rules, krb5_aname_to_localname would
consistently write one byte past the end of a buffer allocated from the
heap.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0523 to this issue.

Only configurations which enable the explicit mapping or rules-based
mapping functionality of krb5_aname_to_localname() are vulnerable.
These configurations are not the default.

Users of Kerberos are advised to upgrade to these erratum packages which
contain backported security patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0523.html">CVE-2004-0523</cve>
                <bugzilla href="http://bugzilla.redhat.com/125001" id="125001">CAN-2004-0523 MIT Kerberos 5: buffer overflows in krb5_aname_to_localname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236006" comment="krb5-libs is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236004" comment="krb5-devel is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236008" comment="krb5-server is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236002" comment="krb5 is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040236010" comment="krb5-workstation is earlier than 0:1.2.7-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040240" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:240: squirrelmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:240-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-240.html" />
          <reference source="CVE" ref_id="CVE-2004-0519" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0519.html" />
          <reference source="CVE" ref_id="CVE-2004-0520" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0520.html" />
          <reference source="CVE" ref_id="CVE-2004-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0521.html" />
    
    <description>SquirrelMail is a webmail package written in PHP.  Multiple
vulnerabilities have been found which affect the version of SquirrelMail
shipped with Red Hat Enterprise Linux 3.

An SQL injection flaw was found in SquirrelMail version 1.4.2 and earlier.
If SquirrelMail is configured to store user addressbooks in the database, a
remote attacker could use this flaw to execute arbitrary SQL statements.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0521 to this issue.

A number of cross-site scripting (XSS) flaws in SquirrelMail version 1.4.2
and earlier could allow remote attackers to execute script as other web
users.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-0519 and CAN-2004-0520 to these issues.

All users of SquirrelMail are advised to upgrade to the erratum package
containing SquirrelMail version 1.4.3a which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-14" />
        <updated date="2004-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0519.html">CVE-2004-0519</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0520.html">CVE-2004-0520</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0521.html">CVE-2004-0521</cve>
                <bugzilla href="http://bugzilla.redhat.com/122512" id="122512">CAN-2004-0519/20/21 XSS and SQL issues in Squirrelmail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240002" comment="squirrelmail is earlier than 0:1.4.3-0.e3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040242" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:242: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:242-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-242.html" />
          <reference source="CVE" ref_id="CVE-2004-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0541.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow was found within the NTLM authentication helper
routine.  If Squid is configured to use the NTLM authentication helper, 
a remote attacker could potentially execute arbitrary code by sending a
lengthy password.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0541 to this issue.

Note: The NTLM authentication helper is not enabled by default in Red Hat
Enterprise Linux 3.  Red Hat Enterprise Linux 2.1 is not vulnerable to this
issue as it shipped with a version of Squid which did not contain the helper.  

Users of Squid should update to this errata package which contains a
backported patch that is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-09" />
        <updated date="2004-06-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0541.html">CVE-2004-0541</cve>
                <bugzilla href="http://bugzilla.redhat.com/125507" id="125507">CAN-2004-0541 Squid NTLM authentication helper overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040242002" comment="squid is earlier than 7:2.5.STABLE3-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040249" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:249: libpng security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:249-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-249.html" />
          <reference source="CVE" ref_id="CVE-2002-1363" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-1363.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.  

During an audit of Red Hat Linux updates, the Fedora Legacy team found a
security issue in libpng that had not been fixed in Red Hat Enterprise
Linux 3.  An attacker could carefully craft a PNG file in such a way that
it would cause an application linked to libpng to crash or potentially
execute arbitrary code when opened by a victim.  

Note: this issue does not affect Red Hat Enterprise Linux 2.1

Users are advised to upgrade to these updated packages that contain a
backported security fix and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-18" />
        <updated date="2004-06-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-1363.html">CVE-2002-1363</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249002" comment="libpng is earlier than 2:1.2.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249004" comment="libpng-devel is earlier than 2:1.2.2-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249008" comment="libpng10-devel is earlier than 0:1.0.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040249006" comment="libpng10 is earlier than 0:1.0.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040255" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:255: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:255-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-255.html" />
          <reference source="CVE" ref_id="CVE-2004-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0427.html" />
          <reference source="CVE" ref_id="CVE-2004-0495" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0495.html" />
          <reference source="CVE" ref_id="CVE-2004-0554" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0554.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw was found in Linux kernel versions 2.4 and 2.6 for x86 and x86_64
that allowed local users to cause a denial of service (system crash) by
triggering a signal handler with a certain sequence of fsave and frstor
instructions.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0554 to this issue.

Another flaw was discovered in an error path supporting the clone()
system call that allowed local users to cause a denial of service
(memory leak) by passing invalid arguments to clone() running in an
infinite loop of a user's program.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0427
to this issue.

Enhancements were committed to the 2.6 kernel by Al Viro which enabled the
Sparse source code checking tool to check for a certain class of kernel
bugs. A subset of these fixes also applies to various drivers in the 2.4
kernel.  Although the majority of these resides in drivers unsupported in
Red Hat Enterprise Linux 3, the flaws could lead to privilege escalation or
access to kernel memory.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0495 to these issues.

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.  These packages contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-06-17" />
        <updated date="2004-06-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0427.html">CVE-2004-0427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0495.html">CVE-2004-0495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0554.html">CVE-2004-0554</cve>
                <bugzilla href="http://bugzilla.redhat.com/125794" id="125794">CAN-2004-0554 local user can get the kernel to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125901" id="125901">[PATCH] CAN-2004-0554: FPU exception handling local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125968" id="125968">last RH kernel affected bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126121" id="126121">CAN-2004-0495 Sparse security fixes backported for 2.4 kernel</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255004" comment="kernel-source is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255002" comment="kernel is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255006" comment="kernel-doc is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255016" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255018" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040255014" comment="kernel-smp is earlier than 0:2.4.21-15.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040259" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:259: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:259-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-259.html" />
          <reference source="CVE" ref_id="CVE-2004-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0600.html" />
          <reference source="CVE" ref_id="CVE-2004-0686" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0686.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.  
  
Evgeny Demidov discovered a flaw in the internal routine used by the Samba
Web Administration Tool (SWAT) in Samba versions 3.0.2 through 3.0.4.  When
decoding base-64 data during HTTP basic authentication, an invalid base-64
character could cause a buffer overflow.  If the SWAT administration
service is enabled, this flaw could allow an attacker to execute arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0600 to this issue.

Additionally, the Samba team discovered a buffer overflow in the code used
to support the 'mangling method = hash' smb.conf option.  Please be aware
that the default setting for this parameter is 'mangling method = hash2'
and therefore not vulnerable.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0686 to this issue.

This release includes the updated upstream version 3.0.4 together with 
backported security patches to correct these issues as well as a number of
post-3.0.4 bug fixes from the Samba subversion repository.  
 
The most important bug fix allows Samba users to change their passwords 
if Microsoft patch KB 828741 (a critical update) had been applied. 
 
All users of Samba should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-22" />
        <updated date="2004-07-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0600.html">CVE-2004-0600</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0686.html">CVE-2004-0686</cve>
                <bugzilla href="http://bugzilla.redhat.com/102715" id="102715">samba spec needs epoch in versioned dependecies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/114436" id="114436">samba consumes all memory then hangs z390 vmachine.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116560" id="116560">Missing BuildRequires: krb5-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117181" id="117181">local variable used before set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119211" id="119211">smb.conf(5) manual page bug if you do not use  UTF-8 based locale</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121356" id="121356">spec file should install libsmbclient.so with executable permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122527" id="122527">Need 'printing = cups' and 'cups options = raw'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122749" id="122749">Samba is unable to read international characters in filenames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123271" id="123271">Users get error message when changing passwords after applying KB828741</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125714" id="125714">NTBackup cannot access samba shares</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126296" id="126296">Requesting updated packages to 3.0.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127909" id="127909">CAN-2004-0600 Buffer Overrun in memcpy()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128227" id="128227">CAN-2004-0686 buffer overflow in 'mangling method = hash' code.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259004" comment="samba-client is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259006" comment="samba-common is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259002" comment="samba is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040259008" comment="samba-swat is earlier than 0:3.0.4-6.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040308" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:308: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-308.html" />
          <reference source="CVE" ref_id="CVE-2004-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0607.html" />
    
    <description>IPSEC uses strong cryptography to provide both authentication and
encryption services.

When configured to use X.509 certificates to authenticate remote hosts,
ipsec-tools versions 0.3.3 and earlier will attempt to verify that host
certificate, but will not abort the key exchange if verification fails.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0607 to this issue.

Users of ipsec-tools should upgrade to this updated package which contains
a backported security patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-29" />
        <updated date="2004-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0607.html">CVE-2004-0607</cve>
                <bugzilla href="http://bugzilla.redhat.com/126568" id="126568">CAN-2004-0607 racoon authentication bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040308002" comment="ipsec-tools is earlier than 0:0.2.5-0.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040323" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:323: lha security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-323.html" />
          <reference source="CVE" ref_id="CVE-2004-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0769.html" />
          <reference source="CVE" ref_id="CVE-2004-0771" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0771.html" />
          <reference source="CVE" ref_id="CVE-2004-0694" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0694.html" />
          <reference source="CVE" ref_id="CVE-2004-0745" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0745.html" />
    
    <description>LHA is an archiving and compression utility for LHarc format archives.

Lukasz Wojtow discovered a stack-based buffer overflow in all versions
of lha up to and including version 1.14.  A carefully created archive could
allow an attacker to execute arbitrary code when a victim extracts or tests
the archive.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0769 to this issue.

Buffer overflows were discovered in the command line processing of all
versions of lha up to and including version 1.14.  If a malicious user
could trick a victim into passing a specially crafted command line to the
lha command, it is possible that arbitrary code could be executed.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-0771 and CAN-2004-0694 to these issues.

Thomas Biege discovered a shell meta character command execution
vulnerability in all versions of lha up to and including 1.14.  An attacker
could create a directory with shell meta characters in its name which could
lead to arbitrary command execution.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0745 to
this issue.

Users of lha should update to this updated package which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0769.html">CVE-2004-0769</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0771.html">CVE-2004-0771</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0694.html">CVE-2004-0694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0745.html">CVE-2004-0745</cve>
                <bugzilla href="http://bugzilla.redhat.com/126740" id="126740">CAN-2004-0694 Buffer overflow in lha (CAN-2004-0745, CAN-2004-0769, CAN-2004-0771)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040323002" comment="lha is earlier than 0:1.14i-10.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040178003" comment="lha is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040342" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:342: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:342-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-342.html" />
          <reference source="CVE" ref_id="CVE-2004-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0488.html" />
          <reference source="CVE" ref_id="CVE-2004-0493" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0493.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

A stack buffer overflow was discovered in mod_ssl that could be triggered
if using the FakeBasicAuth option. If mod_ssl was sent a client certificate
with a subject DN field longer than 6000 characters, a stack overflow
occured if FakeBasicAuth had been enabled. In order to exploit this issue
the carefully crafted malicious certificate would have had to be signed by
a Certificate Authority which mod_ssl is configured to trust. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0488 to this issue.

A remotely triggered memory leak in the Apache HTTP Server earlier than
version 2.0.50 was also discovered.  This allowed a remote attacker to
perform a denial of service attack against the server by forcing it to
consume large amounts of memory.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0493 to this issue.

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-06" />
        <updated date="2004-07-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0488.html">CVE-2004-0488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0493.html">CVE-2004-0493</cve>
                <bugzilla href="http://bugzilla.redhat.com/125046" id="125046">CAN-2004-0488 mod_ssl ssl_util_uuencode_binary() stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126863" id="126863">CAN-2004-0493 folding header DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342004" comment="httpd-devel is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342006" comment="mod_ssl is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040342002" comment="httpd is earlier than 0:2.0.46-32.ent.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040349" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:349: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-349.html" />
          <reference source="CVE" ref_id="CVE-2004-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0748.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

An input filter bug in mod_ssl was discovered in Apache httpd version
2.0.50 and earlier.  A remote attacker could force an SSL connection to be
aborted in a particular state and cause an Apache child process to enter an
infinite loop, consuming CPU resources.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0748 to
this issue.

Additionally, this update includes the following enhancements and bug fixes:

- included an improved version of the mod_cgi module that correctly handles    
  concurrent output on stderr and stdout

- included support for direct lookup of SSL variables using %{SSL:...}
  from mod_rewrite, or using %{...}s from mod_headers

- restored support for use of SHA1-encoded passwords

- added the mod_ext_filter module

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0748.html">CVE-2004-0748</cve>
                <bugzilla href="http://bugzilla.redhat.com/112216" id="112216">4097+ bytes of stderr from cgi script causes script to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/117959" id="117959">Apache autoindex corrupt when > 2GB file in tree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119651" id="119651">HTTP authentication against password file with SHA1 password hashes fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120072" id="120072">please enable mod_ext_filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/120096" id="120096">mod_ssl environment variables not available in mod_rewrite rules</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349004" comment="httpd-devel is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349006" comment="mod_ssl is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040349002" comment="httpd is earlier than 0:2.0.46-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040350" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:350: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-350.html" />
          <reference source="CVE" ref_id="CVE-2004-0642" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0642.html" />
          <reference source="CVE" ref_id="CVE-2004-0643" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0643.html" />
          <reference source="CVE" ref_id="CVE-2004-0644" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0644.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

Several double-free bugs were found in the Kerberos 5 KDC and libraries.  A
remote attacker could potentially exploit these flaws to execuate arbitrary
code.  The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0642 and CAN-2004-0643 to these issues.

A double-free bug was also found in the krb524 server (CAN-2004-0772),
however this issue does not affect Red Hat Enterprise Linux 3 Kerberos
packages.

An infinite loop bug was found in the Kerberos 5 ASN.1 decoder library.  A
remote attacker may be able to trigger this flaw and cause a denial of
service. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0644 to this issue.

When attempting to contact a KDC, the Kerberos libraries will iterate
through the list of configured servers, attempting to contact each in turn.
If one of the servers becomes unresponsive, the client will time out and
contact the next configured server.  When the library attempts to contact
the next KDC, the entire process is repeated.  For applications which must
contact a KDC several times, the accumulated time spent waiting can become
significant.

This update modifies the libraries, notes which server for a given realm
last responded to a request, and attempts to contact that server first
before contacting any of the other configured servers.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-31" />
        <updated date="2004-08-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0642.html">CVE-2004-0642</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0643.html">CVE-2004-0643</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0644.html">CVE-2004-0644</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350006" comment="krb5-libs is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350004" comment="krb5-devel is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350008" comment="krb5-server is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350002" comment="krb5 is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040350010" comment="krb5-workstation is earlier than 0:1.2.7-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040360" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:360: kernel security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:360-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-360.html" />
          <reference source="CVE" ref_id="CVE-2004-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0497.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

During an audit of the Linux kernel, SUSE discovered a flaw that allowed
a user to make unauthorized changes to the group ID of files in certain
circumstances. In the 2.4 kernel, as shipped with Red Hat Enterprise
Linux, the only way this could happen is through the kernel nfs server. A
user on a system that mounted a remote file system from a vulnerable
machine may be able to make unauthorized changes to the group ID of
exported files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0497 to this issue.

Only Red Hat Enterprise Linux systems that are configured to share
file systems via NFS are affected by this issue.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-02" />
        <updated date="2004-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0497.html">CVE-2004-0497</cve>
                <bugzilla href="http://bugzilla.redhat.com/126716" id="126716">CAN-2004-0497 inode_change_ok missing checks allows GID changes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360004" comment="kernel-source is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360002" comment="kernel is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360006" comment="kernel-doc is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360018" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360014" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040360012" comment="kernel-smp is earlier than 0:2.4.21-15.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040373" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:373: gnome-vfs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-373.html" />
          <reference source="CVE" ref_id="CVE-2004-0494" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0494.html" />
    
    <description>GNOME VFS is the GNOME virtual file system. It provides a modular
architecture and ships with several modules that implement support for file
systems, HTTP, FTP, and others.  The extfs backends make it possible to
implement file systems for GNOME VFS using scripts.

Flaws have been found in several of the GNOME VFS extfs backend scripts. 
Red Hat Enterprise Linux ships with vulnerable scripts, but they are not
used by default.  An attacker who is able to influence a user to open a
specially-crafted URI using gnome-vfs could perform actions as that user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0494 to this issue.

Users of Red Hat Enterprise Linux should upgrade to these updated packages,
which remove these unused scripts.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0494.html">CVE-2004-0494</cve>
            <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040373004" comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040373005" comment="gnome-vfs2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040373002" comment="gnome-vfs2 is earlier than 0:2.2.5-2E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040373003" comment="gnome-vfs2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040378" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:378: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:378-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-378.html" />
          <reference source="CVE" ref_id="CVE-2004-0633" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0633.html" />
          <reference source="CVE" ref_id="CVE-2004-0634" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0634.html" />
          <reference source="CVE" ref_id="CVE-2004-0635" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0635.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

The SNMP dissector in Ethereal releases 0.8.15 through 0.10.4 contained a
memory read flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
possibly execute arbitrary code.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0635 to this issue.

The SMB dissector in Ethereal releases 0.9.15 through 0.10.4 contained a
null  pointer flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0634 to this issue.

The iSNS dissector in Ethereal releases 0.10.3 through 0.10.4 contained an
integer overflow flaw.  On a system where Ethereal is running, a remote
attacker could send malicious packets that could cause Ethereal to crash or
possibly execute arbitrary code.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0633 to this issue.

Users of Ethereal should upgrade to these updated packages, which contain
a version that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-28" />
        <updated date="2004-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0633.html">CVE-2004-0633</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0634.html">CVE-2004-0634</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0635.html">CVE-2004-0635</cve>
                <bugzilla href="http://bugzilla.redhat.com/127381" id="127381">CAN-2004-0633/34/35 Multiple problems in Ethereal 0.10.4</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040378004" comment="ethereal-gnome is earlier than 0:0.10.5-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040378002" comment="ethereal is earlier than 0:0.10.5-0.30E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040392" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:392: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-392.html" />
          <reference source="CVE" ref_id="CVE-2004-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0594.html" />
          <reference source="CVE" ref_id="CVE-2004-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0595.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP server.

Stefan Esser discovered a flaw when memory_limit is enabled in versions of
PHP 4 before 4.3.8. If a remote attacker could force the PHP interpreter to
allocate more memory than the memory_limit setting before script execution
begins, then the attacker may be able to supply the contents of a PHP hash
table remotely. This hash table could then be used to execute arbitrary
code as the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0594 to this issue.

This issue has a higher risk when PHP is running on an instance of Apache
which is vulnerable to CAN-2004-0493.  For Red Hat Enterprise Linux 3, this
Apache memory exhaustion issue was fixed by a previous update,
RHSA-2004:342.  It may also be possible to exploit this issue if using a
non-default PHP configuration with the "register_defaults" setting is
changed to "On". Red Hat does not believe that this flaw is exploitable in
the default configuration of Red Hat Enterprise Linux 3.

Stefan Esser discovered a flaw in the strip_tags function in versions of
PHP before 4.3.8.  The strip_tags function is commonly used by PHP scripts
to prevent Cross-Site-Scripting attacks by removing HTML tags from
user-supplied form data.  By embedding NUL bytes into form data, HTML tags
can in some cases be passed intact through the strip_tags function, which
may allow a Cross-Site-Scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0595 to
this issue.  

All users of PHP are advised to upgrade to these updated packages, which
contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-19" />
        <updated date="2004-07-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0594.html">CVE-2004-0594</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0595.html">CVE-2004-0595</cve>
                <bugzilla href="http://bugzilla.redhat.com/127642" id="127642">CAN-2004-0594 PHP memory_limit issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392014" comment="php-odbc is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392010" comment="php-mysql is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392002" comment="php is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392012" comment="php-pgsql is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392004" comment="php-devel is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392006" comment="php-imap is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040392008" comment="php-ldap is earlier than 0:4.3.2-11.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040400" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:400: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:400-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-400.html" />
          <reference source="CVE" ref_id="CVE-2004-0500" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0500.html" />
          <reference source="CVE" ref_id="CVE-2004-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0754.html" />
          <reference source="CVE" ref_id="CVE-2004-0784" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0784.html" />
          <reference source="CVE" ref_id="CVE-2004-0785" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0785.html" />
    
    <description>Gaim is an instant messenger client that can handle multiple protocols.

Buffer overflow bugs were found in the Gaim MSN protocol handler.  In order
to exploit these bugs, an attacker would have to perform a man in the
middle attack between the MSN server and the vulnerable Gaim client.  Such
an attack could allow arbitrary code execution.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0500
to this issue.

Buffer overflow bugs have been found in the Gaim URL decoder, local
hostname resolver, and the RTF message parser.  It is possible that a
remote attacker could send carefully crafted data to a vulnerable client
and lead to a crash or arbitrary code execution.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0785 to this issue.

A shell escape bug has been found in the Gaim smiley theme file
installation.  When a user installs a smiley theme, which is contained
within a tar file, the unarchiving of the data is done in an unsafe manner.
An attacker could create a malicious smiley theme that would execute
arbitrary commands if the theme was installed by the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0784 to this issue.

An integer overflow bug has been found in the Gaim Groupware message
receiver.  It is possible that if a user connects to a malicious server,
an attacker could send carefully crafted data which could lead to arbitrary
code execution on the victims machine.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0754 to
this issue.

Users of Gaim are advised to upgrade to this updated package which
contains Gaim version 0.82 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-07" />
        <updated date="2004-09-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0500.html">CVE-2004-0500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0754.html">CVE-2004-0754</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0784.html">CVE-2004-0784</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0785.html">CVE-2004-0785</cve>
                <bugzilla href="http://bugzilla.redhat.com/126842" id="126842">CAN-2004-0500 Gaim MSN protocol vulnerabilities</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040400002" comment="gaim is earlier than 1:0.82.1-0.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040402" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:402: libpng security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-402.html" />
          <reference source="CVE" ref_id="CVE-2002-1363" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-1363.html" />
          <reference source="CVE" ref_id="CVE-2004-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0597.html" />
          <reference source="CVE" ref_id="CVE-2004-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0598.html" />
          <reference source="CVE" ref_id="CVE-2004-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0599.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

During a source code audit, Chris Evans discovered several buffer overflows
in libpng.  An attacker could create a carefully crafted PNG file in such a
way that it would cause an application linked with libpng to execute
arbitrary code when the file was opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0597 to these issues.  

In addition, this audit discovered a potential NULL pointer dereference in
libpng (CAN-2004-0598) and several integer overflow issues (CAN-2004-0599).
An attacker could create a carefully crafted PNG file in such a way that
it would cause an application linked with libpng to crash when the file was
opened by the victim.

Red Hat would like to thank Chris Evans for discovering these issues.

For users of Red Hat Enterprise Linux 2.1 these patches also include a more
complete fix for the out of bounds memory access flaw (CAN-2002-1363). 

All users are advised to update to the updated libpng packages which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2002-1363.html">CVE-2002-1363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0597.html">CVE-2004-0597</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0598.html">CVE-2004-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0599.html">CVE-2004-0599</cve>
                <bugzilla href="http://bugzilla.redhat.com/127869" id="127869">CAN-2004-0597/98/99 multiple problems in libpng 1.2.5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402004" comment="libpng10-devel is earlier than 0:1.0.13-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180009" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402002" comment="libpng10 is earlier than 0:1.0.13-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180007" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402006" comment="libpng is earlier than 2:1.2.2-25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180003" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040402008" comment="libpng-devel is earlier than 2:1.2.2-25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040180005" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040409" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:409: sox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-409.html" />
          <reference source="CVE" ref_id="CVE-2004-0557" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0557.html" />
    
    <description>SoX (Sound eXchange) is a sound file format converter. SoX can convert
between many different digitized sound formats and perform simple sound
manipulation functions, including sound effects.

Buffer overflows existed in the parsing of WAV file header fields. It was
possible that a malicious WAV file could have caused arbitrary code to be
executed when the file was played or converted.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0557
to these issues.

All users of sox should upgrade to these updated packages, which resolve
these issues as well as fix a number of minor bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-07-29" />
        <updated date="2004-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0557.html">CVE-2004-0557</cve>
                <bugzilla href="http://bugzilla.redhat.com/79151" id="79151">largefile support missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/91144" id="91144">SoX's soxplay doesn't except paths containg spaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/102499" id="102499">sox RPM does not install soxmix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127502" id="127502">-r option dumps core on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128158" id="128158">CAN-2004-0557 buffer overflows in sox</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040409004" comment="sox-devel is earlier than 0:12.17.4-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040409005" comment="sox-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040409002" comment="sox is earlier than 0:12.17.4-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040409003" comment="sox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040412" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:412: kdelibs, kdebase security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:412-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-412.html" />
          <reference source="CVE" ref_id="CVE-2004-0689" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0689.html" />
          <reference source="CVE" ref_id="CVE-2004-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0746.html" />
          <reference source="CVE" ref_id="CVE-2004-0721" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0721.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment.
The kdebase packages include core applications for the K Desktop Environment.

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create
temporary directories with predictable names.  A local attacker could
prevent KDE applications from functioning correctly, or overwrite files
owned by other users by creating malicious symlinks.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-0689
to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web
browser Konqueror allows websites to set cookies for certain country
specific secondary top level domains.  An attacker within one of the
affected domains could construct a cookie which would be sent to all other
websites within the domain leading to a session fixation attack.  This
issue does not affect popular domains such as .co.uk, .co.in, or .com.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the
Konqueror web browser.  This issue could allow a malicious website to show
arbitrary content in a named frame of a different browser window.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0746 to this issue.

All users of KDE are advised to upgrade to these erratum packages,
which contain backported patches from the KDE team for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-05" />
        <updated date="2004-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0689.html">CVE-2004-0689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0746.html">CVE-2004-0746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0721.html">CVE-2004-0721</cve>
                <bugzilla href="http://bugzilla.redhat.com/128462" id="128462">CAN-2004-0721 Konqueror frame injection spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128693" id="128693">CAN-2004-0689 Predictable temporary filenames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129228" id="129228">CAN-2004-0746 Konqueror Cross-Domain Cookie Injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412002" comment="kdebase is earlier than 6:3.1.3-5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412004" comment="kdebase-devel is earlier than 6:3.1.3-5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412006" comment="kdelibs is earlier than 6:3.1.3-6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040412008" comment="kdelibs-devel is earlier than 6:3.1.3-6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040413" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:413: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-413.html" />
          <reference source="CVE" ref_id="CVE-2004-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0178.html" />
          <reference source="CVE" ref_id="CVE-2004-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0415.html" />
          <reference source="CVE" ref_id="CVE-2004-0447" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0447.html" />
          <reference source="CVE" ref_id="CVE-2004-0535" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0535.html" />
          <reference source="CVE" ref_id="CVE-2004-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0587.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered flaws in the Linux kernel when handling file
offset pointers.  These consist of invalid conversions of 64 to 32-bit file
offset pointers and possible race conditions.  A local unprivileged user
could make use of these flaws to access large portions of kernel memory. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0415 to this issue.  

These packages contain a patch written by Al Viro to correct these flaws. 
Red Hat would like to thank iSEC Security Research for disclosing this
issue and a number of vendor-sec participants for reviewing and working on
the patch to this issue.

In addition, these packages correct a number of minor security issues:

An bug in the e1000 network driver.  This bug could be used by local users
to leak small amounts of kernel memory (CAN-2004-0535).

A bug in the SoundBlaster 16 code which does not properly handle certain
sample sizes.  This flaw could be used by local users to crash a system 
(CAN-2004-0178).

A possible NULL-pointer dereference in the Linux kernel prior to 2.4.26 on
the Itanium platform could allow a local user to crash a system
(CAN-2004-0447).

Inappropriate permissions on /proc/scsi/qla2300/HbaApiNode (CAN-2004-0587).

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-03" />
        <updated date="2004-08-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0178.html">CVE-2004-0178</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0415.html">CVE-2004-0415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0447.html">CVE-2004-0447</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0535.html">CVE-2004-0535</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0587.html">CVE-2004-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/120527" id="120527">CAN-2004-0447 [PATCH] IPF kernel crashes under gdb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121045" id="121045">CAN-2004-0178 Soundblaster 16 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125168" id="125168">CAN-2004-0535 e1000 kernel memory information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126396" id="126396">CAN-2004-0587 Bad permissions on qla* drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126402" id="126402">CAN-2004-0447 NULL-pointer dereference in unwind.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126414" id="126414">CAN-2004-0415 file offset pointer signedness issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413004" comment="kernel-source is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413002" comment="kernel is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413006" comment="kernel-doc is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413016" comment="kernel-hugemem is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413018" comment="kernel-BOOT is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413008" comment="kernel-unsupported is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040413014" comment="kernel-smp is earlier than 0:2.4.21-15.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040414" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:414: qt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:414-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-414.html" />
          <reference source="CVE" ref_id="CVE-2004-0691" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0691.html" />
          <reference source="CVE" ref_id="CVE-2004-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0692.html" />
          <reference source="CVE" ref_id="CVE-2004-0693" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0693.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3.   An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-20" />
        <updated date="2004-08-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0691.html">CVE-2004-0691</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0692.html">CVE-2004-0692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0693.html">CVE-2004-0693</cve>
                <bugzilla href="http://bugzilla.redhat.com/128720" id="128720">CAN-2004-0691 BMP decoder heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129502" id="129502">CAN-2004-0692 XPM decoder integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414008" comment="qt-ODBC is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414009" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414014" comment="qt-designer is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414015" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414002" comment="qt is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414003" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414004" comment="qt-config is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414005" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414010" comment="qt-MySQL is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414011" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414006" comment="qt-devel is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414007" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040414012" comment="qt-PostgreSQL is earlier than 1:3.1.2-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040414013" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040421" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:421: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-421.html" />
          <reference source="CVE" ref_id="CVE-2004-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0597.html" />
          <reference source="CVE" ref_id="CVE-2004-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0599.html" />
          <reference source="CVE" ref_id="CVE-2004-0718" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0718.html" />
          <reference source="CVE" ref_id="CVE-2004-0722" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0722.html" />
          <reference source="CVE" ref_id="CVE-2004-0757" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0757.html" />
          <reference source="CVE" ref_id="CVE-2004-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0758.html" />
          <reference source="CVE" ref_id="CVE-2004-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0759.html" />
          <reference source="CVE" ref_id="CVE-2004-0760" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0760.html" />
          <reference source="CVE" ref_id="CVE-2004-0761" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0761.html" />
          <reference source="CVE" ref_id="CVE-2004-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0762.html" />
          <reference source="CVE" ref_id="CVE-2004-0763" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0763.html" />
          <reference source="CVE" ref_id="CVE-2004-0764" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0764.html" />
          <reference source="CVE" ref_id="CVE-2004-0765" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0765.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A number of flaws have been found in Mozilla 1.4 that have been fixed in
the Mozilla 1.4.3 release: 

Zen Parse reported improper input validation to the SOAPParameter object
constructor leading to an integer overflow and controllable heap
corruption.  Malicious JavaScript could be written to utilize this flaw and
could allow arbitrary code execution.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0722 to
this issue.

During a source code audit, Chris Evans discovered a buffer overflow and
integer overflows which affect the libpng code inside Mozilla. An attacker
could create a carefully crafted PNG file in such a way that it would cause
Mozilla to crash or execute arbitrary code when the image was viewed.
(CAN-2004-0597, CAN-2004-0599)

Zen Parse reported a flaw in the POP3 capability.  A malicious POP3 server
could send a carefully crafted response that would cause a heap overflow
and potentially allow execution of arbitrary code as the user running
Mozilla. (CAN-2004-0757)

Marcel Boesch found a flaw that allows a CA certificate to be imported with
a DN the same as that of the built-in CA root certificates, which can cause
a denial of service to SSL pages, as the malicious certificate is treated
as invalid. (CAN-2004-0758)

Met - Martin Hassman reported a flaw in Mozilla that could allow malicious
Javascript code to upload local files from a users machine without
requiring confirmation. (CAN-2004-0759)

Mindlock Security reported a flaw in ftp URI handling.  By using a NULL
character (%00) in a ftp URI, Mozilla can be confused into opening a
resource as a different MIME type. (CAN-2004-0760)

Mozilla does not properly prevent a frame in one domain from injecting
content into a frame that belongs to another domain, which facilitates
website spoofing and other attacks, also known as the frame injection
vulnerability.  (CAN-2004-0718)

Tolga Tarhan reported a flaw that can allow a malicious webpage to use a
redirect sequence to spoof the security lock icon that makes a webpage
appear to be encrypted.  (CAN-2004-0761)

Jesse Ruderman reported a security issue that affects a number of browsers
including Mozilla that could allow malicious websites to install arbitrary
extensions by using interactive events to manipulate the XPInstall Security
dialog box. (CAN-2004-0762)

Emmanouel Kellinis discovered a caching flaw in Mozilla which allows
malicious websites to spoof certificates of trusted websites via
redirects and Javascript that uses the "onunload" method. (CAN-2004-0763)

Mozilla allowed malicious websites to hijack the user interface via the
"chrome" flag and XML User Interface Language (XUL) files. (CAN-2004-0764)

The cert_TestHostName function in Mozilla only checks the hostname portion
of a certificate when the hostname portion of the URI is not a fully
qualified domain name (FQDN).  This flaw could be used for spoofing if an
attacker had control of machines on a default DNS search path. (CAN-2004-0765)

All users are advised to update to these erratum packages which contain a
snapshot of Mozilla 1.4.3 including backported fixes and are not vulnerable
to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-04" />
        <updated date="2004-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0597.html">CVE-2004-0597</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0599.html">CVE-2004-0599</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0718.html">CVE-2004-0718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0722.html">CVE-2004-0722</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0757.html">CVE-2004-0757</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0758.html">CVE-2004-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0759.html">CVE-2004-0759</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0760.html">CVE-2004-0760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0761.html">CVE-2004-0761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0762.html">CVE-2004-0762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0763.html">CVE-2004-0763</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0764.html">CVE-2004-0764</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0765.html">CVE-2004-0765</cve>
                <bugzilla href="http://bugzilla.redhat.com/127186" id="127186">CAN-2004-0758 Overriding built-in certificate leading to error -8182 (DoS), especially exploitable by email</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127338" id="127338">CAN-2004-0718 frame injection (spoofing) vuln in Mozilla before 1.7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129123" id="129123">Numerous security issues fixed in Mozilla 1.4.3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421002" comment="mozilla is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040421008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040434" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:434: redhat-config-nfs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-434.html" />
          <reference source="CVE" ref_id="CVE-2004-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0750.html" />
    
    <description>The redhat-config-nfs package includes a graphical user interface for
creating, modifying, and deleting nfs shares.

John Buswell discovered a flaw in redhat-config-nfs that could lead to
incorrect permissions on exported shares when exporting to multiple
hosts.  This could cause an option such as "all_squash" to not be
applied to all of the listed hosts.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0750 to
this issue.

Additionally, a bug was found that prevented redhat-config-nfs from being
run if hosts didn't have options set in /etc/exports.

All users of redhat-config-nfs are advised to upgrade to these updated
packages as well as checking their NFS shares directly or via the
/etc/exports file for any incorrectly set options.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-22" />
        <updated date="2004-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0750.html">CVE-2004-0750</cve>
                <bugzilla href="http://bugzilla.redhat.com/107997" id="107997">CVE-2004-0750 [PATCH] /etc/exports has incorrect syntax for multiple hosts with a single mount point</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040434002" comment="redhat-config-nfs is earlier than 0:1.0.13-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040434003" comment="redhat-config-nfs is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040436" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:436: rsync security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-436.html" />
          <reference source="CVE" ref_id="CVE-2004-0792" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0792.html" />
    
    <description>The rsync program synchronizes files over a network. 
 
Versions of rsync up to and including version 2.6.2 contain a path 
sanitization issue.  This issue could allow an attacker to read or write 
files outside of the rsync directory.  This vulnerability is only 
exploitable when an rsync server is enabled and is not running within a
chroot. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0792 to this issue.

Users of rsync are advised to upgrade to this updated package, which 
contains a backported patch and is not affected by this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-01" />
        <updated date="2004-09-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0792.html">CVE-2004-0792</cve>
                <bugzilla href="http://bugzilla.redhat.com/130050" id="130050">CAN-2004-0792 rsync path sanitizing bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040436002" comment="rsync is earlier than 0:2.5.7-5.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040441" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:441: ruby security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:441-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-441.html" />
          <reference source="CVE" ref_id="CVE-2004-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0755.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

Andres Salomon reported an insecure file permissions flaw in the CGI
session management of Ruby.  FileStore created world readable files that
could allow a malicious local user the ability to read CGI session data. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0755 to this issue.

Users are advised to upgrade to this erratum package, which contains a
backported patch to CGI::Session FileStore.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0755.html">CVE-2004-0755</cve>
                <bugzilla href="http://bugzilla.redhat.com/130065" id="130065">CAN-2004-0755 ruby insecure file permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441010" comment="irb is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441002" comment="ruby is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040441006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040446" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:446: openoffice.org security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:446-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-446.html" />
          <reference source="CVE" ref_id="CVE-2004-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0752.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Secunia Research reported an issue with the handling of temporary files.  A
malicious local user could use this flaw to access the contents of another
user's open documents.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0752 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0752.html">CVE-2004-0752</cve>
                <bugzilla href="http://bugzilla.redhat.com/130132" id="130132">CAN-2004-0752 openoffice temporary file information leakage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446006" comment="openoffice.org-i18n is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446002" comment="openoffice.org is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040446004" comment="openoffice.org-libs is earlier than 0:1.1.0-16.14.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040447" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:447: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:447-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-447.html" />
          <reference source="CVE" ref_id="CVE-2004-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0753.html" />
          <reference source="CVE" ref_id="CVE-2004-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0782.html" />
          <reference source="CVE" ref_id="CVE-2004-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0783.html" />
          <reference source="CVE" ref_id="CVE-2004-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0788.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

[Updated 15th September 2004]
Packages have been updated to correct a bug which caused the xpm loader
to fail.

During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was
discovered in the BMP image processor of gdk-pixbuf.  An attacker could
create a carefully crafted BMP file which would cause an application
to enter an infinite loop and not respond to user input when the file was
opened by a victim.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0753 to this issue.

During a security audit, Chris Evans discovered a stack and a heap overflow
in the XPM image decoder. An attacker could create a carefully crafted XPM
file which could cause an application linked with gtk2 to crash or possibly
execute arbitrary code when the file was opened by a victim.
(CAN-2004-0782, CAN-2004-0783)

Chris Evans also discovered an integer overflow in the ICO image decoder.
An attacker could create a carefully crafted ICO file which could cause an
application linked with gtk2 to crash when the file is opened by a victim.
(CAN-2004-0788)

These packages have also been updated to correct a bug which caused the xpm
loader to fail.

Users of gdk-pixbuf are advised to upgrade to these packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0753.html">CVE-2004-0753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0782.html">CVE-2004-0782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0783.html">CVE-2004-0783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0788.html">CVE-2004-0788</cve>
                <bugzilla href="http://bugzilla.redhat.com/130455" id="130455">CAN-2004-0753 bmp image loader DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130711" id="130711">CAN-2004-0782/3/8 GTK XPM decoder issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040447002" comment="gdk-pixbuf is earlier than 1:0.22.0-11.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040449" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:449: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-449.html" />
          <reference source="CVE" ref_id="CVE-2004-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0558.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

Alvaro Martinez Echevarria reported a bug in the CUPS Internet Printing
Protocol (IPP) implementation in versions of CUPS prior to 1.1.21.  An
attacker could send a carefully crafted UDP packet to the IPP port which
could cause CUPS to stop listening to the port and result in a denial of
service.  In order to exploit this bug, an attacker would need to have the
ability to send a UDP packet to the IPP port (by default 631).  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0558 to this issue.

All users of cups should upgrade to these updated packages, which contain a
backported patch as well as a fix for a non-exploitable off-by-one bug.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0558.html">CVE-2004-0558</cve>
                <bugzilla href="http://bugzilla.redhat.com/130650" id="130650">CAN-2004-0558 DOS in cups browsing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449004" comment="cups-devel is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449006" comment="cups-libs is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040449002" comment="cups is earlier than 1:1.1.17-13.3.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040451" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:451: spamassassin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-451.html" />
          <reference source="CVE" ref_id="CVE-2004-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0796.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug has been found in SpamAssassin versions below 2.64.
A malicious attacker could construct a message in such a way that would
cause spamassassin to stop responding, potentially preventing the delivery
or filtering of email.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0796 to this issue.

Users of SpamAssassin should update to these updated packages which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0796.html">CVE-2004-0796</cve>
                <bugzilla href="http://bugzilla.redhat.com/129337" id="129337">CAN-2004-0796 DOS attack open to certain malformed messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451002" comment="spamassassin is earlier than 0:2.55-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040451003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040462" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:462: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:462-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-462.html" />
          <reference source="CVE" ref_id="CVE-2004-0832" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0832.html" />
    
    <description>Squid is a full-featured Web proxy cache.

An out of bounds memory read bug was found within the NTLM authentication
helper routine.  If Squid is configured to use the NTLM authentication
helper, a remote attacker could send a carefully crafted NTLM
authentication packet and cause Squid to crash.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0832
to this issue.

Note: The NTLM authentication helper is not enabled by default in Red Hat
Enterprise Linux 3.  Red Hat Enterprise Linux 2.1 is not vulnerable to this
issue as it shipped with a version of Squid which did not contain the
vulnerable helper. 

Users of Squid should update to this erratum package, which contains a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0832.html">CVE-2004-0832</cve>
                <bugzilla href="http://bugzilla.redhat.com/131750" id="131750">CAN-2004-0832 Certain malformed NTLMSSP packets could crash the NTLM helpers provided by Squid</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040462002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040463" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:463: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:463-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-463.html" />
          <reference source="CVE" ref_id="CVE-2004-0747" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0747.html" />
          <reference source="CVE" ref_id="CVE-2004-0751" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0751.html" />
          <reference source="CVE" ref_id="CVE-2004-0786" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0786.html" />
          <reference source="CVE" ref_id="CVE-2004-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0809.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

Four issues have been discovered affecting releases of the Apache HTTP 2.0
Server, up to and including version 2.0.50:

Testing using the Codenomicon HTTP Test Tool performed by the Apache
Software Foundation security group and Red Hat uncovered an input
validation issue in the IPv6 URI parsing routines in the apr-util library. 
If a remote attacker sent a request including a carefully crafted URI, an
httpd child process could be made to crash.  This issue is not believed to
allow arbitrary code execution on Red Hat Enterprise Linux.  This issue
also does not represent a significant denial of service attack as requests
will continue to be handled by other Apache child processes.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0786 to this issue.

The Swedish IT Incident Centre (SITIC) reported a buffer overflow in the
expansion of environment variables during configuration file parsing.  This
issue could allow a local user to gain 'apache' privileges if an httpd
process can be forced to parse a carefully crafted .htaccess file written
by a local user.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0747 to this issue.

An issue was discovered in the mod_ssl module which could be triggered if
the server is configured to allow proxying to a remote SSL server.  A
malicious remote SSL server could force an httpd child process to crash by
sending a carefully crafted response header.  This issue is not believed to
allow execution of arbitrary code.  This issue also does not represent a
significant Denial of Service attack as requests will continue to be
handled by other Apache child processes.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0751 to
this issue.

An issue was discovered in the mod_dav module which could be triggered for
a location where WebDAV authoring access has been configured.  A malicious
remote client which is authorized to use the LOCK method could force an
httpd child process to crash by sending a particular sequence of LOCK
requests.  This issue does not allow execution of arbitrary code.  This
issue also does not represent a significant Denial of Service attack as
requests will continue to be handled by other Apache child processes.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0809 to this issue. 

Users of the Apache HTTP server should upgrade to these updated packages,
which contain backported patches that address these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0747.html">CVE-2004-0747</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0751.html">CVE-2004-0751</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0786.html">CVE-2004-0786</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0809.html">CVE-2004-0809</cve>
                <bugzilla href="http://bugzilla.redhat.com/131900" id="131900">CAN-2004-0747/51/86 Apache issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463004" comment="httpd-devel is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463006" comment="mod_ssl is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040463002" comment="httpd is earlier than 0:2.0.46-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040465" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:465: imlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-465.html" />
          <reference source="CVE" ref_id="CVE-2004-0817" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0817.html" />
    
    <description>Imlib is an image loading and rendering library.

Several heap overflow flaws were found in the imlib BMP image handler.   An
attacker could create a carefully crafted BMP file in such a way that it
could cause an application linked with imlib to execute arbitrary code when
the file was opened by a victim.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue.

Users of imlib should update to this updated package which contains
backported patches and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0817.html">CVE-2004-0817</cve>
                <bugzilla href="http://bugzilla.redhat.com/130909" id="130909">CAN-2004-0817 heap overflow in BMP decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465006" comment="imlib-cfgeditor is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465007" comment="imlib-cfgeditor is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465002" comment="imlib is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465003" comment="imlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040465004" comment="imlib-devel is earlier than 1:1.9.13-13.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465005" comment="imlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040466" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:466: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:466-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-466.html" />
          <reference source="CVE" ref_id="CVE-2004-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0753.html" />
          <reference source="CVE" ref_id="CVE-2004-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0782.html" />
          <reference source="CVE" ref_id="CVE-2004-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0783.html" />
          <reference source="CVE" ref_id="CVE-2004-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0788.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was
discovered in the BMP image processor of gtk2.  An attacker could create a
carefully crafted BMP file which would cause an application to enter an
infinite loop and not respond to user input when the file was opened by a
victim.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0753 to this issue.

During a security audit Chris Evans discovered a stack and a heap overflow
in the XPM image decoder.  An attacker could create a carefully crafted XPM
file which could cause an application linked with gtk2 to crash or possibly
execute arbitrary code when the file was opened by a victim. 
(CAN-2004-0782, CAN-2004-0783)

Chris Evans also discovered an integer overflow in the ICO image decoder. 
An attacker could create a carefully crafted ICO file which could cause an
application linked with gtk2 to crash when the file was opened by a victim.
(CAN-2004-0788)

This updated gtk2 package also fixes a few key combination bugs on various
X servers, such as Hummingbird, ReflectionX, and X-Win32. If a server was
configured to use the Swiss German, Swiss French, or France French keyboard
layouts, Mode_Switched characters were unable to be entered within GTK
based applications.

Users of gtk2 are advised to upgrade to these packages which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-15" />
        <updated date="2004-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0753.html">CVE-2004-0753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0782.html">CVE-2004-0782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0783.html">CVE-2004-0783</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0788.html">CVE-2004-0788</cve>
                <bugzilla href="http://bugzilla.redhat.com/130450" id="130450">CAN-2004-0753 bmp image loader DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130711" id="130711">CAN-2004-0782/3/8 GTK XPM decoder issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040466002" comment="gtk2 is earlier than 0:2.2.4-8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040466004" comment="gtk2-devel is earlier than 0:2.2.4-8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040467" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:467: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:467-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-467.html" />
          <reference source="CVE" ref_id="CVE-2004-0807" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0807.html" />
          <reference source="CVE" ref_id="CVE-2004-0808" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0808.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

The Samba team has discovered a denial of service bug in the smbd daemon. 
A defect in smbd's ASN.1 parsing allows an attacker to send a specially
crafted packet during the authentication request which will send the newly
spawned smbd process into an infinite loop.  Given enough of these packets,
it is possible to exhaust the available memory on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0807 to this issue.

Additionally the Samba team has also discovered a denial of service bug in
the nmbd daemon.  It is possible that an attacker could send a specially
crafted UDP packet which could allow the attacker to anonymously
crash nmbd.  This issue only affects nmbd daemons which are configured to
process domain logons.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0808 to this issue.

Users of Samba should upgrade to these updated packages, which contain an
upgrade to Samba-3.0.7, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-23" />
        <updated date="2004-09-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0807.html">CVE-2004-0807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0808.html">CVE-2004-0808</cve>
                <bugzilla href="http://bugzilla.redhat.com/132207" id="132207">CAN-2004-0807/8 Samba 3 DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467004" comment="samba-client is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467006" comment="samba-common is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467002" comment="samba is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040467008" comment="samba-swat is earlier than 0:3.0.7-1.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040478" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:478: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-478.html" />
          <reference source="CVE" ref_id="CVE-2004-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0419.html" />
          <reference source="CVE" ref_id="CVE-2004-0687" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0687.html" />
          <reference source="CVE" ref_id="CVE-2004-0688" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0688.html" />
          <reference source="CVE" ref_id="CVE-2004-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0692.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low level functionality which full fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

During a source code audit, Chris Evans discovered several stack overflow
flaws and an integer overflow flaw in the X.Org libXpm library used to
decode XPM (X PixMap) images. An attacker could create a carefully crafted
XPM file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687,
CAN-2004-0688, and CAN-2004-0692 to these issues.

A flaw was found in the X Display Manager (XDM). XDM is shipped with Red
Hat Enterprise Linux, but is not used by default. XDM opened a chooserFd
TCP socket even if the DisplayManager.requestPort parameter was set to 0.
This allowed authorized users to access a machine remotely via X, even if
the administrator had configured XDM to refuse such connections. Although
XFree86 4.3.0 was not vulnerable to this issue, Red Hat Enterprise Linux 3
contained a backported patch which introduced this flaw. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0419 to this issue.

Users are advised to upgrade to these erratum packages, which contain
backported security patches to correct these and a number of other issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-04" />
        <updated date="2004-10-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0419.html">CVE-2004-0419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0687.html">CVE-2004-0687</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0688.html">CVE-2004-0688</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0692.html">CVE-2004-0692</cve>
                <bugzilla href="http://bugzilla.redhat.com/124901" id="124901">CAN-2004-0419 xdm opens random tcp sockets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126205" id="126205">xdm walks physical memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129744" id="129744">Radeon driver (7000m) TVDAC output too high for DELL Server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131121" id="131121">CAN-2004-0687/8 libXpm stack and integer overflows.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132121" id="132121">archexec script not in XFree86-devel package</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478012" comment="XFree86-xdm is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478016" comment="XFree86-libs-data is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478058" comment="XFree86-doc is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478002" comment="XFree86 is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478054" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478014" comment="XFree86-libs is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478060" comment="XFree86-sdk is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478008" comment="XFree86-xfs is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478046" comment="XFree86-Xnest is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478056" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478018" comment="XFree86-base-fonts is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478006" comment="XFree86-font-utils is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478050" comment="XFree86-tools is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478048" comment="XFree86-Xvfb is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478010" comment="XFree86-twm is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478052" comment="XFree86-xauth is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040478004" comment="XFree86-devel is earlier than 0:4.3.0-69.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040480" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:480: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-480.html" />
          <reference source="CVE" ref_id="CVE-2004-0827" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0827.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System.

A heap overflow flaw has been discovered in the ImageMagick image handler.
An attacker could create a carefully crafted BMP file in such a way that it
could cause ImageMagick to execute arbitrary code when processing the
image.  The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-0827 to this issue.

Users of ImageMagick should upgrade to this updated package, which contains
a backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0827.html">CVE-2004-0827</cve>
                <bugzilla href="http://bugzilla.redhat.com/130807" id="130807">CAN-2004-0827 heap overflow in BMP decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480004" comment="ImageMagick-devel is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480006" comment="ImageMagick-perl is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480002" comment="ImageMagick is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040480008" comment="ImageMagick-c++ is earlier than 0:5.5.6-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040486" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:486: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-486.html" />
          <reference source="CVE" ref_id="CVE-2004-0902" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0902.html" />
          <reference source="CVE" ref_id="CVE-2004-0903" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0903.html" />
          <reference source="CVE" ref_id="CVE-2004-0904" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0904.html" />
          <reference source="CVE" ref_id="CVE-2004-0905" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0905.html" />
          <reference source="CVE" ref_id="CVE-2004-0908" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0908.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Jesse Ruderman discovered a cross-domain scripting bug in Mozilla.  If
a user is tricked into dragging a javascript link into another frame or
page, it becomes possible for an attacker to steal or modify sensitive
information from that site.  Additionally, if a user is tricked into
dragging two links in sequence to another window (not frame), it is
possible for the attacker to execute arbitrary commands.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0905 to this issue.

Gael Delalleau discovered an integer overflow which affects the BMP
handling code inside Mozilla. An attacker could create a carefully crafted
BMP file in such a way that it would cause Mozilla to crash or execute
arbitrary code when the image is viewed.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0904 to
this issue.

Georgi Guninski discovered a stack-based buffer overflow in the vCard
display routines.  An attacker could create a carefully crafted vCard file
in such a way that it would cause Mozilla to crash or execute arbitrary
code when viewed.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0903 to this issue.

Wladimir Palant discovered a flaw in the way javascript interacts with
the clipboard.  It is possible that an attacker could use malicious
javascript code to steal sensitive data which has been copied into the
clipboard.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0908 to this issue.

Georgi Guninski discovered a heap based buffer overflow in the "Send
Page" feature.  It is possible that an attacker could construct a link in
such a way that a user attempting to forward it could result in a crash or
arbitrary code execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0902 to this issue.

Users of Mozilla should update to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-09-30" />
        <updated date="2004-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0902.html">CVE-2004-0902</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0903.html">CVE-2004-0903</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0904.html">CVE-2004-0904</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0905.html">CVE-2004-0905</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0908.html">CVE-2004-0908</cve>
                <bugzilla href="http://bugzilla.redhat.com/133012" id="133012">CAN-2004-0905 javascript link dragging information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133013" id="133013">CAN-2004-0905 javascript link dragging information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133014" id="133014">CAN-2004-0904 BMP integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133015" id="133015">CAN-2004-0904 BMP integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133016" id="133016">CAN-2004-0903 VCard buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133017" id="133017">CAN-2004-0903 VCard buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133021" id="133021">CAN-2004-0908 javascript clipboard information leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133022" id="133022">CAN-2004-0908 javascript clipboard information leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133023" id="133023">CAN-2004-0902 "send page" heap based buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133024" id="133024">CAN-2004-0902 "send page" heap based buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486002" comment="mozilla is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040486008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040489" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:489: rh-postgresql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:489-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-489.html" />
          <reference source="CVE" ref_id="CVE-2004-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0977.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS) that supports almost all SQL constructs (including transactions,
subselects, and user-defined types and functions).

Trustix has identified improper temporary file usage in the
make_oidjoins_check script.  It is possible that an attacker could
overwrite arbitrary file contents as the user running the
make_oidjoins_check script.  This script has been removed from the RPM file
since it has no use to ordinary users.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0977 to
this issue.

Additionally, the following non-security issues have been addressed:

- Fixed a low probability risk for loss of recently committed transactions.

- Fixed a low probability risk for loss of older data due to failure to 
  update transaction status.

- A lock file problem that sometimes prevented automatic restart after a 
  system crash has been fixed.

All users of rh-postgresql should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0977.html">CVE-2004-0977</cve>
                <bugzilla href="http://bugzilla.redhat.com/130814" id="130814">PostgreSQL can lose committed transactions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130989" id="130989">a bug in rh-postgresql.spec file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134090" id="134090">Postgres's init script does not remove stale PID file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136300" id="136300">CAN-2004-0977 temporary file vulnerabilities in make_oidjoins_check script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136949" id="136949">PostgreSQL data loss risk and minor security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489020" comment="rh-postgresql-jdbc is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489008" comment="rh-postgresql-docs is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489010" comment="rh-postgresql-contrib is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489002" comment="rh-postgresql is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489018" comment="rh-postgresql-python is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489014" comment="rh-postgresql-pl is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489012" comment="rh-postgresql-devel is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489022" comment="rh-postgresql-test is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489016" comment="rh-postgresql-tcl is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489006" comment="rh-postgresql-server is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040489004" comment="rh-postgresql-libs is earlier than 0:7.3.8-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040537" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:537: openmotif security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:537-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-537.html" />
          <reference source="CVE" ref_id="CVE-2004-0687" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0687.html" />
          <reference source="CVE" ref_id="CVE-2004-0688" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0688.html" />
          <reference source="CVE" ref_id="CVE-2004-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0914.html" />
    
    <description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.  

During a source code audit, Chris Evans and others discovered several stack
overflow flaws and an integer overflow flaw in the libXpm library used to
decode XPM (X PixMap) images. A vulnerable version of this library was
found within OpenMotif. An attacker could create a carefully crafted
XPM file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names
CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.

Users of OpenMotif are advised to upgrade to these erratum packages, which
contain backported security patches to the embedded libXpm library.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-02" />
        <updated date="2004-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0687.html">CVE-2004-0687</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0688.html">CVE-2004-0688</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0914.html">CVE-2004-0914</cve>
                <bugzilla href="http://bugzilla.redhat.com/134631" id="134631">CAN-2004-0687 libxpm flaws affect OpenMotif (CAN-2004-0688, CAN-2004-0914)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537004" comment="openmotif-devel is earlier than 0:2.2.3-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537005" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537002" comment="openmotif is earlier than 0:2.2.3-4.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537003" comment="openmotif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040537006" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040537007" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040543" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:543: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:543-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-543.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-0923" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0923.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect xpdf.  CUPS contains a copy of the xpdf code used
for parsing PDF files and is therefore affected by these bugs.  An attacker
who has the ability to send a malicious PDF file to a printer could cause
CUPS to crash or possibly execute arbitrary code.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0888 to this issue.

When set up to print to a shared printer via Samba, CUPS would authenticate
with that shared printer using a username and password.  By default, the
username and password used to connect to the Samba share is written
into the error log file.  A local user who is able to read the error log
file could collect these usernames and passwords.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0923 to this issue.

These updated packages also include a fix that prevents some CUPS
configuration files from being accidentally replaced.

All users of CUPS should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-22" />
        <updated date="2004-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0923.html">CVE-2004-0923</cve>
                <bugzilla href="http://bugzilla.redhat.com/99461" id="99461">cups configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132034" id="132034">mime.types was updated - not copied to mime.types.rpmnew</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134599" id="134599">CAN-2004-0923 Log file information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135378" id="135378">CAN-2004-0888 xpdf issues affect cups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543004" comment="cups-devel is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543006" comment="cups-libs is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040543002" comment="cups is earlier than 1:1.1.17-13.3.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040546" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:546: cyrus-sasl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:546-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-546.html" />
          <reference source="CVE" ref_id="CVE-2004-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0884.html" />
    
    <description>The cyrus-sasl package contains the Cyrus implementation of SASL.  SASL is
the Simple Authentication and Security Layer, a method for adding
authentication support to connection-based protocols.

At application startup, libsasl and libsasl2 attempts to build a list
of all available SASL plug-ins which are available on the system.  To do
so, the libraries search for and attempt to load every shared library found
within the plug-in directory.  This location can be set with the SASL_PATH
environment variable.

In situations where an untrusted local user can affect the environment of a
privileged process, this behavior could be exploited to run arbitrary code
with the privileges of a setuid or setgid application.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0884 to this issue.

Users of cyrus-sasl should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-07" />
        <updated date="2004-10-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0884.html">CVE-2004-0884</cve>
                <bugzilla href="http://bugzilla.redhat.com/134657" id="134657">CAN-2004-0884 privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134979" id="134979">cyrus-sasl causes crashes with ldap</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546008" comment="cyrus-sasl-plain is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546009" comment="cyrus-sasl-plain is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546004" comment="cyrus-sasl-devel is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546005" comment="cyrus-sasl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546010" comment="cyrus-sasl-md5 is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546011" comment="cyrus-sasl-md5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546006" comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546007" comment="cyrus-sasl-gssapi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040546002" comment="cyrus-sasl is earlier than 0:2.1.15-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040546003" comment="cyrus-sasl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040549" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:549: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-549.html" />
          <reference source="CVE" ref_id="CVE-2004-0138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0138.html" />
          <reference source="CVE" ref_id="CVE-2004-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0619.html" />
          <reference source="CVE" ref_id="CVE-2004-0685" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0685.html" />
          <reference source="CVE" ref_id="CVE-2004-0812" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0812.html" />
          <reference source="CVE" ref_id="CVE-2004-0883" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0883.html" />
          <reference source="CVE" ref_id="CVE-2004-0949" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0949.html" />
          <reference source="CVE" ref_id="CVE-2004-1068" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1068.html" />
          <reference source="CVE" ref_id="CVE-2004-1070" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1070.html" />
          <reference source="CVE" ref_id="CVE-2004-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1071.html" />
          <reference source="CVE" ref_id="CVE-2004-1072" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1072.html" />
          <reference source="CVE" ref_id="CVE-2004-1073" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1073.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This update includes fixes for several security issues:

A missing serialization flaw in unix_dgram_recvmsg was discovered that
affects kernels prior to 2.4.28.  A local user could potentially make
use of a race condition in order to gain privileges.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1068 to this issue.

Paul Starzetz of iSEC discovered various flaws in the ELF binary
loader affecting kernels prior to 2.4.28.  A local user could use thse
flaws to gain read access to executable-only binaries or possibly gain
privileges. (CAN-2004-1070, CAN-2004-1071, CAN-2004-1072, CAN-2004-1073)

A flaw when setting up TSS limits was discovered that affects AMD AMD64
and Intel EM64T architecture kernels prior to 2.4.23.  A local user could
use this flaw to cause a denial of service (crash) or possibly gain
privileges.  (CAN-2004-0812)

An integer overflow flaw was discovered in the ubsec_keysetup function
in the Broadcom 5820 cryptonet driver.  On systems using this driver,
a local user could cause a denial of service (crash) or possibly gain
elevated privileges.  (CAN-2004-0619)

Stefan Esser discovered various flaws including buffer overflows in
the smbfs driver affecting kernels prior to 2.4.28.  A local user may be
able to cause a denial of service (crash) or possibly gain privileges.
In order to exploit these flaws the user would require control of
a connected Samba server.  (CAN-2004-0883, CAN-2004-0949)

SGI discovered a bug in the elf loader that affects kernels prior to
2.4.25 which could be triggered by a malformed binary.  On
architectures other than x86, a local user could create a malicious
binary which could cause a denial of service (crash).  (CAN-2004-0136)

Conectiva discovered flaws in certain USB drivers affecting kernels
prior to 2.4.27 which used the copy_to_user function on uninitialized
structures.  These flaws could allow local users to read small amounts
of kernel memory.  (CAN-2004-0685)

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-02" />
        <updated date="2004-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0138.html">CVE-2004-0138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0619.html">CVE-2004-0619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0685.html">CVE-2004-0685</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0812.html">CVE-2004-0812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0883.html">CVE-2004-0883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0949.html">CVE-2004-0949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1068.html">CVE-2004-1068</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1070.html">CVE-2004-1070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1071.html">CVE-2004-1071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1072.html">CVE-2004-1072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1073.html">CVE-2004-1073</cve>
                <bugzilla href="http://bugzilla.redhat.com/127258" id="127258">CAN-2004-0619 Broadcom 5820 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127915" id="127915">CAN-2004-0138 Verify interpreter arch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127918" id="127918">CAN-2004-0685 usb sparse fixes in 2.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134720" id="134720">CAN-2004-0883 smbfs potential DOS (CAN-2004-0949)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134874" id="134874">CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134981" id="134981">CAN-2004-0138 Program crashes the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140710" id="140710">CAN-2004-1068 Missing serialisation in unix_dgram_recvmsg</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549004" comment="kernel-source is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549002" comment="kernel is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549006" comment="kernel-doc is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549014" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549016" comment="kernel-hugemem is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549018" comment="kernel-BOOT is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549008" comment="kernel-unsupported is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040549012" comment="kernel-smp is earlier than 0:2.4.21-20.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040562" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:562: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:562-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-562.html" />
          <reference source="CVE" ref_id="CVE-2004-0885" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0885.html" />
          <reference source="CVE" ref_id="CVE-2004-0942" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0942.html" />
          <reference source="CVE" ref_id="CVE-2004-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1834.html" />
    
    <description>The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue has been discovered in the mod_ssl module when configured to use
the "SSLCipherSuite" directive in directory or location context.  If a
particular location context has been configured to require a specific set
of cipher suites, then a client will be able to access that location using
any cipher suite allowed by the virtual host configuration.   The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0885 to this issue.

An issue has been discovered in the handling of white space in request
header lines using MIME folding.  A malicious client could send a carefully
crafted request, forcing the server to consume large amounts of memory,
leading to a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0942 to this issue.

Several minor bugs were also discovered, including:

- In the mod_cgi module, problems that arise when CGI scripts are 
  invoked from SSI pages by mod_include using the "#include virtual" 
  syntax have been fixed.

- In the mod_dav_fs module, problems with the handling of indirect locks
  on the S/390x platform have been fixed.

Users of the Apache HTTP server who are affected by these issues should
upgrade to these updated packages, which contain backported patches.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0885.html">CVE-2004-0885</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0942.html">CVE-2004-0942</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1834.html">CVE-2004-1834</cve>
                <bugzilla href="http://bugzilla.redhat.com/134825" id="134825">CAN-2004-0885 SSLCipherSuite bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138064" id="138064">CAN-2004-0942 Memory consumption DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562004" comment="httpd-devel is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562006" comment="mod_ssl is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040562002" comment="httpd is earlier than 0:2.0.46-44.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040569" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:569: mysql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-569.html" />
          <reference source="CVE" ref_id="CVE-2004-0381" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0381.html" />
          <reference source="CVE" ref_id="CVE-2004-0388" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0388.html" />
          <reference source="CVE" ref_id="CVE-2004-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0457.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes a number of small bugs, including some potential
security problems associated with careless handling of temporary files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0381, CAN-2004-0388, and CAN-2004-0457 to these
issues.

A number of additional security issues that affect mysql have been
corrected in the source package.  These include CAN-2004-0835,
CAN-2004-0836, CAN-2004-0837, and CAN-2004-0957.  Red Hat Enterprise Linux
3 does not ship with the mysql-server package and is therefore not affected
by these issues.

This update also allows 32-bit and 64-bit libraries to be installed
concurrently on the same system.

All users of mysql should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0381.html">CVE-2004-0381</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0388.html">CVE-2004-0388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0457.html">CVE-2004-0457</cve>
                <bugzilla href="http://bugzilla.redhat.com/58732" id="58732">/etc/init.d/mysqld doesn't wait for server to start</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108779" id="108779">Always timeout error starting MySQL Daemon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/112693" id="112693">mysqlhotcopy of local Fedora DB broken after upgrade from RH9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/113960" id="113960">[PATCH] Bug fix + enhancement for mysql_setpermission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/115165" id="115165">botched string concat ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119442" id="119442">CAN-2004-0381 mysqlbug temporary file vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124352" id="124352">Cannot drop databases</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128852" id="128852">database service should start earlier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129409" id="129409">linking with 'mysql --libs' doesent seem to work correctly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130348" id="130348">CAN-2004-0457 mysqlhotcopy insecure temporary file vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133993" id="133993">Service mysqld restart</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135387" id="135387">CAN-2004-0835 MySQL flaws (CAN-2004-0836, CAN-2004-0837, CAN-2004-0957)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569002" comment="mysql is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569004" comment="mysql-server is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569008" comment="mysql-bench is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040569006" comment="mysql-devel is earlier than 0:3.23.58-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040577" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:577: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:577-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-577.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1307.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files. TIFF is a widely used file
format for bitmapped images. 

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. An attacker who has the ability to trick
a user into opening a malicious TIFF file could cause the application
linked to libtiff to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found.  An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause the application linked to libtiff to crash
or possibly execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0803 to
this issue.

All users are advised to upgrade to these errata packages, which contain
fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-22" />
        <updated date="2004-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1307.html">CVE-2004-1307</cve>
                <bugzilla href="http://bugzilla.redhat.com/134847" id="134847">CAN-2004-0803 buffer overflows in libtiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134850" id="134850">CAN-2004-0886 multiple integer overflows in libtiff</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040577002" comment="libtiff is earlier than 0:3.5.7-20.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040577004" comment="libtiff-devel is earlier than 0:3.5.7-20.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040583" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:583: nfs-utils security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:583-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-583.html" />
          <reference source="CVE" ref_id="CVE-2004-1014" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1014.html" />
          <reference source="CVE" ref_id="CVE-2004-0946" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0946.html" />
    
    <description>The nfs-utils package provides a daemon for the kernel NFS server and
related tools, providing a much higher level of performance than the
traditional Linux NFS server used by most users.

This package also contains the showmount program. Showmount queries
the mount daemon on a remote host for information about the NFS
(Network File System) server on the remote host.

SGI reported that the statd daemon did not properly handle the SIGPIPE
signal.  A misconfigured or malicious peer could cause statd to crash,
leading to a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1014 to this issue.

Arjan van de Ven discovered a buffer overflow in rquotad.  On 64-bit
architectures, an improper integer conversion can lead to a buffer
overflow.  An attacker with access to an NFS share could send a specially
crafted request which could lead to the execution of arbitrary code.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0946 to this issue.

Additionally, this updated package addresses the following issues:

- The UID of the nfsnobody account has been fixed for 32-bit and 64-bit
machines. Because the st_uid field of the stat structure is an unsigned
integer, an actual value of -2 cannot be used when creating the account, so
the decimal value of -2 is used. On a 32-bit machine, the decimal value of
-2 is 65534 but on a 64-bit machine it is 4294967294. This errata enables
the nfs-utils post-install script to detect the target architecture, so an
appropriate decimal value is used.

All users of nfs-utils should upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1014.html">CVE-2004-1014</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0946.html">CVE-2004-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/139611" id="139611">CAN-2004-1014 DoS in statd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040583002" comment="nfs-utils is earlier than 0:1.0.6-33EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040072003" comment="nfs-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040585" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:585: xchat security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:585-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-585.html" />
          <reference source="CVE" ref_id="CVE-2004-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0409.html" />
    
    <description>X-Chat is a graphical IRC chat client for the X Window System.

A stack buffer overflow has been fixed in the SOCKSv5 proxy code.
An attacker could create a malicious SOCKSv5 proxy server in such a way
that X-Chat would execute arbitrary code if a victim configured X-Chat to
use the proxy.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0409 to this issue.

Users of X-Chat should upgrade to this erratum package, which contains a
backported security patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-27" />
        <updated date="2004-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0409.html">CVE-2004-0409</cve>
                <bugzilla href="http://bugzilla.redhat.com/121333" id="121333">CAN-2004-0409 XChat buffer overflow in socks5 proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135238" id="135238">CAN-2004-0409 XChat buffer overflow in socks5 proxy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040585002" comment="xchat is earlier than 1:2.0.4-4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040585003" comment="xchat is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040586" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:586: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-586.html" />
          <reference source="CVE" ref_id="CVE-2004-0968" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0968.html" />
    
    <description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

This errata fixes several bugs in the GNU C Library.

Fixes include (in addition to enclosed Bugzilla entries):

- fixed 32-bit atomic operations on 64-bit powerpc
- fixed -m32 -I /usr/include/nptl compilation on AMD64
- NPTL &lt;pthread.h> should now be usable in C++ code or -pedantic -std=c89 C
- rwlocks are now available also in the _POSIX_C_SOURCE=200112L namespace
- pthread_once is no longer throw(), as the callback routine might throw
- pthread_create now correctly returns EAGAIN when thread couldn't be
created because of lack of memory
- fixed NPTL stack freeing in case of pthread_create failure with detached
thread
- fixed pthread_mutex_timedlock on i386 and AMD64
- Itanium gp saving fix in linuxthreads
- fixed s390/s390x unwinding tests done during cancellation if stack frames
are small
- fixed fnmatch(3) backslash handling
- fixed out of memory behaviour of syslog(3)
- resolver ID randomization
- fixed fim (NaN, NaN)
- glob(3) fixes for dangling symlinks
- catchsegv fixed to work with both 32-bit and 64-bit binaries on x86-64,
s390x and ppc
- fixed reinitialization of _res when using NPTL stack cache
- updated bug reporting instructions, removed glibcbug script
- fixed infinite loop in iconv with some options
- fixed inet_aton return value
- CPU friendlier busy waiting in linuxthreads on EM64T and IA-64
- avoid blocking/masking debug signal in linuxthreads
- fixed locale program output when neither LC_ALL nor LANG is set
- fixed using of unitialized memory in localedef
- fixed mntent_r escape processing
- optimized mtrace script
- linuxthread_db fixes on ppc64
- cfi instructions in x86-64 linuxthreads vfork
- some _POSIX_C_SOURCE=200112L namespace fixes

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0968.html">CVE-2004-0968</cve>
                <bugzilla href="http://bugzilla.redhat.com/103415" id="103415">Weird string in date printing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118574" id="118574">malloc exhausts memory to fast in mulithreaded program</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123583" id="123583">getnameinfo does not use /etc/hosts for lookup of V4MAPPED addresses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127606" id="127606">__builtin_expect's prototype does not expect int args; assert feeds it just that</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130254" id="130254">glibc's traceback() fails when called from an exception handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132204" id="132204">glibc-nis-performance.patch causes gdm to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132816" id="132816">glibc in RHEL 3 needs to have syslog.c updated to cvs version 1.42</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136318" id="136318">CAN-2004-0968 temporary file vulnerabilities in catchsegv script</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586012" comment="glibc-common is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586006" comment="glibc-headers is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586008" comment="nptl-devel is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586004" comment="glibc-devel is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586016" comment="glibc-debug is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586010" comment="glibc-profile is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586002" comment="glibc is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586014" comment="nscd is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040586018" comment="glibc-utils is earlier than 0:2.3.2-95.30" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040591" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:591: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:591-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-591.html" />
          <reference source="CVE" ref_id="CVE-2004-0918" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0918.html" />
    
    <description>Squid is a full-featured Web proxy cache.

iDEFENSE reported a flaw in the squid SNMP module.  This flaw could allow
an attacker who has the ability to send arbitrary packets to the SNMP port
to restart the server, causing it to drop all open connections.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0918 to this issue.

All users of squid should update to this erratum package, which contains a
backport of the security fix for this vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0918.html">CVE-2004-0918</cve>
                <bugzilla href="http://bugzilla.redhat.com/135319" id="135319">CAN-2004-0918 SNMP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040591002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040592" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:592: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:592-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-592.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format
(PDF) files.

During a source code audit, Chris Evans and others discovered a number
of integer overflow bugs that affected all versions of xpdf.  An
attacker could construct a carefully crafted PDF file that could cause
xpdf to crash or possibly execute arbitrary code when opened.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0888 to this issue.

Users of xpdf are advised to upgrade to this errata package, which contains
a backported patch correcting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-27" />
        <updated date="2004-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
                <bugzilla href="http://bugzilla.redhat.com/135393" id="135393">CAN-2004-0888 xpdf integer overflows (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592002" comment="xpdf is earlier than 1:2.02-9.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040604" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:604: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:604-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-604.html" />
          <reference source="CVE" ref_id="CVE-2004-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0891.html" />
    
    <description>The gaim application is a multi-protocol instant messaging client.

A buffer overflow has been discovered in the MSN protocol handler.  When
receiving unexpected sequence of MSNSLP messages, it is possible that an
attacker could cause an internal buffer overflow, leading to a crash or
possible code execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0891 to this issue.

This updated gaim package also fixes multiple user interface, protocol, and
error handling problems, including an ICQ communication encoding issue.

Additionally, these updated packages have compiled gaim as a PIE (position
independent executable) for added protection against future security
vulnerabilities.

All users of gaim should upgrade to this updated package, which includes
various bug fixes, as well as a backported security patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-10-20" />
        <updated date="2004-10-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0891.html">CVE-2004-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/135678" id="135678">CAN-2004-0891 MSN protocol buffer overflow.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040604002" comment="gaim is earlier than 1:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040609" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:609: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:609-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-609.html" />
          <reference source="CVE" ref_id="CVE-2004-0938" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0938.html" />
          <reference source="CVE" ref_id="CVE-2004-0960" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0960.html" />
          <reference source="CVE" ref_id="CVE-2004-0961" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0961.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A number of flaws were found in FreeRADIUS versions prior to 1.0.1.  An
attacker who is able to send packets to the server could construct
carefully constructed packets in such a way as to cause the server to
consume memory or crash.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2004-0938, CAN-2004-0960, and
CAN-2004-0961 to these issues.

Users of FreeRADIUS should update to these erratum packages that contain
FreeRADIUS 1.0.1, which is not vulnerable to these issues and also corrects
a number of bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0938.html">CVE-2004-0938</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0960.html">CVE-2004-0960</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0961.html">CVE-2004-0961</cve>
                <bugzilla href="http://bugzilla.redhat.com/127162" id="127162">zlib-devel is missing from BuildRequires in spec file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127168" id="127168">rebuilding freeradius picks up system libeap rather than package libeap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130606" id="130606">Missing buildrequires in freediag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130613" id="130613">radiusd.conf specifies other pam-auth than file installed in /etc/pam.d</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135825" id="135825">CAN-2004-0938 Freeradius &lt; 1.0.1 DoS and remote crash (CAN-2004-0960, CAN-2004-0961)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609004" comment="freeradius-mysql is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609006" comment="freeradius-postgresql is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609008" comment="freeradius-unixODBC is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040609002" comment="freeradius is earlier than 0:1.0.1-1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040612" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:612: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:612-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-612.html" />
          <reference source="CVE" ref_id="CVE-2004-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0914.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low level functionality which full fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow flaws in the X.Org libXpm library used to decode
XPM (X PixMap) images have been found and addressed. An attacker could
create a carefully crafted XPM file which would cause an application to
crash or potentially execute arbitrary code if opened by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0914 to this issue.

Users are advised to upgrade to these erratum packages, which contain
backported security patches as well as other bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-20" />
        <updated date="2004-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0914.html">CVE-2004-0914</cve>
                <bugzilla href="http://bugzilla.redhat.com/136164" id="136164">CAN-2004-0914 libXpm integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612012" comment="XFree86-xdm is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612016" comment="XFree86-libs-data is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612058" comment="XFree86-doc is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612002" comment="XFree86 is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612054" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612014" comment="XFree86-libs is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612060" comment="XFree86-sdk is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612008" comment="XFree86-xfs is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612046" comment="XFree86-Xnest is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612056" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612018" comment="XFree86-base-fonts is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612006" comment="XFree86-font-utils is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612050" comment="XFree86-tools is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612048" comment="XFree86-Xvfb is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612010" comment="XFree86-twm is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612052" comment="XFree86-xauth is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040612004" comment="XFree86-devel is earlier than 0:4.3.0-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040615" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:615: libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:615-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-615.html" />
          <reference source="CVE" ref_id="CVE-2004-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0989.html" />
    
    <description>libxml2 is a library for manipulating XML files.

Multiple buffer overflow bugs have been found in libxml2 versions prior to
2.6.14.  If an attacker can trick a user into passing a specially crafted
FTP URL or FTP proxy URL to an application that uses the vulnerable
functions of libxml2, it could be possible to execute arbitrary code.  
Additionally, if an attacker can return a specially crafted DNS request to
libxml2, it could be possible to execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0989 to this issue.

All users are advised to upgrade to this updated package, which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-12" />
        <updated date="2004-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0989.html">CVE-2004-0989</cve>
                <bugzilla href="http://bugzilla.redhat.com/137264" id="137264">CAN-2004-0989 multiple buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615002" comment="libxml2 is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090003" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615004" comment="libxml2-devel is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090005" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040615006" comment="libxml2-python is earlier than 0:2.5.10-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040090007" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040632" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:632: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:632-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-632.html" />
          <reference source="CVE" ref_id="CVE-2004-0882" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0882.html" />
          <reference source="CVE" ref_id="CVE-2004-0930" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0930.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

During a code audit, Stefan Esser discovered a buffer overflow in Samba
versions prior to 3.0.8 when handling unicode filenames.  An authenticated
remote user could exploit this bug which may lead to arbitrary code
execution on the server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0882 to this issue. Red Hat
believes that the Exec-Shield technology (enabled by default since Update
3) will block attempts to remotely exploit this vulnerability on x86
architectures.

Additionally, a bug was found in the input validation routines in versions
of Samba prior to 3.0.8 that caused the smbd process to consume abnormal
amounts of system memory.  An authenticated remote user could exploit this
bug to cause a denial of service.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0930 to this issue.

Users of Samba should upgrade to these updated packages, which contain
backported security patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-11-16" />
        <updated date="2004-11-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0882.html">CVE-2004-0882</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0930.html">CVE-2004-0930</cve>
                <bugzilla href="http://bugzilla.redhat.com/134640" id="134640">CAN-2004-0882 unicode parsing overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138325" id="138325">CAN-2004-0930 wildcard remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632004" comment="samba-client is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632006" comment="samba-common is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632002" comment="samba is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040632008" comment="samba-swat is earlier than 0:3.0.7-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040634" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:634: zip security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:634-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-634.html" />
          <reference source="CVE" ref_id="CVE-2004-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1010.html" />
    
    <description>The zip program is an archiving utility which can create ZIP-compatible
archives.

A buffer overflow bug has been discovered in zip when handling long file
names.  An attacker could create a specially crafted path which could
cause zip to crash or execute arbitrary instructions.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1010 to this issue.

Users of zip should upgrade to this updated package, which contains
backported patches and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2004-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1010.html">CVE-2004-1010</cve>
                <bugzilla href="http://bugzilla.redhat.com/138228" id="138228">CAN-2004-1010 buffer overflow when creating archive containing very long filenames.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040634002" comment="zip is earlier than 0:2.3-16.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040634003" comment="zip is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040635" version="505" class="patch">
      <metadata>
        <title>RHSA-2004:635: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:635-04" ref_url="https://rhn.redhat.com/errata/RHSA-2004-635.html" />
          <reference source="CVE" ref_id="CVE-2004-0983" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0983.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A flaw was dicovered in the CGI module of Ruby.  If empty data is sent by
the POST method to the CGI script which requires MIME type
multipart/form-data, it can get stuck in a loop.  A remote attacker could
trigger this flaw and cause a denial of service.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0983 to this issue.

Users are advised to upgrade to this erratum package, which contains a
backported patch to cgi.rb.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-17" />
        <updated date="2005-01-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0983.html">CVE-2004-0983</cve>
                <bugzilla href="http://bugzilla.redhat.com/138362" id="138362">CAN-2004-0983 Denial of Service in Ruby</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635010" comment="irb is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635002" comment="ruby is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040635006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040441007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040636" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:636: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:636-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-636.html" />
          <reference source="CVE" ref_id="CVE-2004-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0981.html" />
          <reference source="CVE" ref_id="CVE-2004-0827" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0827.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System.

A buffer overflow flaw was discovered in the ImageMagick image handler.
An attacker could create a carefully crafted image file with an improper
EXIF information in such a way that it would cause ImageMagick to execute
arbitrary code when processing the image. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0981 to
this issue.

David Eisenstein has reported that our previous fix for CAN-2004-0827, a
heap overflow flaw, was incomplete.  An attacker could create a carefully
crafted BMP file in such a way that it could cause ImageMagick to execute
arbitrary code when processing the image. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0827 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-08" />
        <updated date="2004-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0981.html">CVE-2004-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0827.html">CVE-2004-0827</cve>
                <bugzilla href="http://bugzilla.redhat.com/130807" id="130807">CAN-2004-0827 heap overflow in BMP decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138383" id="138383">CAN-2004-0981 buffer overflow in ImageMagick's EXIF parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636004" comment="ImageMagick-devel is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636006" comment="ImageMagick-perl is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636002" comment="ImageMagick is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040636008" comment="ImageMagick-c++ is earlier than 0:5.5.6-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040638" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:638: gd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:638-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-638.html" />
          <reference source="CVE" ref_id="CVE-2004-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0941.html" />
          <reference source="CVE" ref_id="CVE-2004-0990" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0990.html" />
    
    <description>The gd packages contain a graphics library used for the dynamic creation of
images such as PNG and JPEG. 

Several buffer overflows were reported in various memory allocation calls.
An attacker could create a carefully crafted image file in such a way that
it could cause ImageMagick to execute arbitrary code when processing the
image. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0990 to these issues.  

While researching the fixes to these overflows, additional buffer overflows
were discovered in calls to gdMalloc.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0941 to
these issues.  

Users of gd should upgrade to these updated packages, which contain a
backported security patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2005-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0941.html">CVE-2004-0941</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0990.html">CVE-2004-0990</cve>
                <bugzilla href="http://bugzilla.redhat.com/137246" id="137246">CAN-2004-0990 integer overflow in PNG handling.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138808" id="138808">CAN-2004-0941 additional overflows in gd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638006" comment="gd-devel is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638007" comment="gd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638004" comment="gd-progs is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638005" comment="gd-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040638002" comment="gd is earlier than 0:1.8.4-12.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040638003" comment="gd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040650" version="504" class="patch">
      <metadata>
        <title>RHSA-2004:650: libxml security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:650-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-650.html" />
          <reference source="CVE" ref_id="CVE-2004-0110" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0110.html" />
          <reference source="CVE" ref_id="CVE-2004-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0989.html" />
    
    <description>The libxml package contains a library for manipulating XML files.

Multiple buffer overflow bugs have been found in libxml versions prior to
2.6.14.  If an attacker can trick a user into passing a specially crafted
FTP URL or FTP proxy URL to an application that uses the vulnerable
functions of libxml, it could be possible to execute arbitrary code.  
Additionally, if an attacker can return a specially crafted DNS request to
libxml, it could be possible to execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0989 to this issue.

Yuuichi Teranishi discovered a flaw in libxml versions prior to 2.6.6.
When fetching a remote resource via FTP or HTTP, libxml uses special
parsing routines. These routines can overflow a buffer if passed a very
long URL. If an attacker is able to find an application using libxml that
parses remote resources and allows them to influence the URL, then this
flaw could be used to execute arbitrary code. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0110
to this issue.

All users are advised to upgrade to this updated package, which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2005-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0110.html">CVE-2004-0110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0989.html">CVE-2004-0989</cve>
                <bugzilla href="http://bugzilla.redhat.com/139090" id="139090">CAN-2004-0110 multiple buffer overflows (CAN-2004-0989)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040650004" comment="libxml-devel is earlier than 1:1.8.17-9.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040650005" comment="libxml-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040650002" comment="libxml is earlier than 1:1.8.17-9.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040650003" comment="libxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040651" version="503" class="patch">
      <metadata>
        <title>RHSA-2004:651: imlib security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:651-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-651.html" />
          <reference source="CVE" ref_id="CVE-2004-1025" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1025.html" />
          <reference source="CVE" ref_id="CVE-2004-1026" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1026.html" />
    
    <description>The imlib packages contain an image loading and rendering library.

Pavel Kankovsky discovered several heap overflow flaws that were found in
the imlib image handler. An attacker could create a carefully crafted image
file in such a way that it could cause an application linked with imlib to
execute arbitrary code when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1025 to this issue.

Additionally, Pavel discovered several integer overflow flaws that were
found in the imlib image handler. An attacker could create a carefully
crafted image file in such a way that it could cause an application linked
with imlib to execute arbitrary code or crash when the file was opened by a
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1026 to this issue.

Users of imlib should update to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1025.html">CVE-2004-1025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1026.html">CVE-2004-1026</cve>
                <bugzilla href="http://bugzilla.redhat.com/138516" id="138516">CAN-2004-1025 Multiple imlib issues. (CAN-2004-1026)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651006" comment="imlib-cfgeditor is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465007" comment="imlib-cfgeditor is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651002" comment="imlib is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465003" comment="imlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040651004" comment="imlib-devel is earlier than 1:1.9.13-13.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040465005" comment="imlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040654" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:654: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:654-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-654.html" />
          <reference source="CVE" ref_id="CVE-2004-1036" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1036.html" />
    
    <description>SquirrelMail is a webmail package written in PHP.

A cross-site scripting bug has been found in SquirrelMail.  This issue
could allow an attacker to send a mail with a carefully crafted header,
which could result in causing the victim's machine to execute a malicious
script. The Common Vulnerabilities and Exposures project has assigned the
name CAN-2004-1036 to this issue.

Additionally, the following issues have been addressed:

- updated splash screens
- HIGASHIYAMA Masato's patch to improve Japanese support
- real 1.4.3a tarball
- config_local.php and default_pref in /etc/squirrelmail/ to match upstream   
  RPM.

Please note that it is possible that upgrading to this package may remove
your SquirrelMail configuration files due to a bug in the RPM package. 
Upgrading will prevent this from happening in the future.

Users of SquirrelMail are advised to upgrade to this updated package which
contains a patched version of SquirrelMail version 1.43a and is not
vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1036.html">CVE-2004-1036</cve>
                <bugzilla href="http://bugzilla.redhat.com/112769" id="112769">The login page says Red Hat Linux instead of Fedora/RHEL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/125638" id="125638">config_local.php is not listed as a config file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139739" id="139739">CAN-2004-1036 Cross Site Scripting in encoded text</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040654002" comment="squirrelmail is earlier than 0:1.4.3a-7.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040670" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:670: samba security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:670-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-670.html" />
          <reference source="CVE" ref_id="CVE-2004-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1154.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

Greg MacManus of iDEFENSE Labs has discovered an integer overflow bug in
Samba versions prior to 3.0.10.  An authenticated remote user could exploit
this bug which may lead to arbitrary code execution on the Samba server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1154 to this issue.

Users of Samba should upgrade to these updated packages, which contain
backported security patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-16" />
        <updated date="2004-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1154.html">CVE-2004-1154</cve>
                <bugzilla href="http://bugzilla.redhat.com/142472" id="142472">CAN-2004-1154 Samba authenticated remote root</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670004" comment="samba-client is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064005" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670006" comment="samba-common is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670002" comment="samba is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040670008" comment="samba-swat is earlier than 0:3.0.9-1.3E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040064009" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040687" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:687: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:687-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-687.html" />
          <reference source="CVE" ref_id="CVE-2004-0958" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0958.html" />
          <reference source="CVE" ref_id="CVE-2004-0959" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0959.html" />
          <reference source="CVE" ref_id="CVE-2004-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1018.html" />
          <reference source="CVE" ref_id="CVE-2004-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1019.html" />
          <reference source="CVE" ref_id="CVE-2004-1065" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1065.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP.  PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow.  An attacker could create a carefully crafted image file in such
a way that if parsed by a PHP script using the exif extension it could
cause a crash or potentially execute arbitrary code.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

An information disclosure bug was discovered in the parsing of "GPC"
variables in PHP (query strings or cookies, and POST form data).  If
particular scripts used the values of the GPC variables, portions of the
memory space of an httpd child process could be revealed to the client. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0958 to this issue.

A file access bug was discovered in the parsing of "multipart/form-data"
forms, used by PHP scripts which allow file uploads.  In particular
configurations, some scripts could allow a malicious client to upload files
to an arbitrary directory where the "apache" user has write access.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0959 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions.  These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Various issues were discovered in the use of the "select" system call in
PHP, which could be triggered if PHP is used in an Apache configuration
where the number of open files (such as virtual host log files) exceeds the
default process limit of 1024.  Workarounds are now included for some of
these issues.

The "phpize" shell script included in PHP can be used to build third-party
extension modules.  A build issue was discovered in the "phpize" script on
some 64-bit platforms which prevented correct operation.

The "pcntl" extension module is now enabled in the command line PHP
interpreter, /usr/bin/php.  This module enables process control features 
such as "fork" and "kill" from PHP scripts.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-21" />
        <updated date="2004-12-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0958.html">CVE-2004-0958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0959.html">CVE-2004-0959</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1018.html">CVE-2004-1018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1019.html">CVE-2004-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1065.html">CVE-2004-1065</cve>
                <bugzilla href="http://bugzilla.redhat.com/131412" id="131412">Include process control extension, pcntl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131562" id="131562">phpize is broken on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132003" id="132003">fopen doesn't work across remote connections while under Apache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134971" id="134971">CAN-2004-0958 PHP variable parsing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134975" id="134975">CAN-2004-0959 PHP arbitrary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141132" id="141132">CAN-2004-1019 information disclosure issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142056" id="142056">CAN-2004-1065 ext/exif/exif.c - exif_read_data() overflow on long sectionname</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687014" comment="php-odbc is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687010" comment="php-mysql is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687002" comment="php is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687012" comment="php-pgsql is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687004" comment="php-devel is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687006" comment="php-imap is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040687008" comment="php-ldap is earlier than 0:4.3.2-19.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20040689" version="502" class="patch">
      <metadata>
        <title>RHSA-2004:689: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2004:689-01" ref_url="https://rhn.redhat.com/errata/RHSA-2004-689.html" />
          <reference source="CVE" ref_id="CVE-2004-0565" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0565.html" />
          <reference source="CVE" ref_id="CVE-2004-1016" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1016.html" />
          <reference source="CVE" ref_id="CVE-2004-1017" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1017.html" />
          <reference source="CVE" ref_id="CVE-2004-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1137.html" />
          <reference source="CVE" ref_id="CVE-2004-1144" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1144.html" />
          <reference source="CVE" ref_id="CVE-2004-1234" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1234.html" />
          <reference source="CVE" ref_id="CVE-2004-1335" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1335.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

Petr Vandrovec discovered a flaw in the 32bit emulation code affecting the
Linux 2.4 kernel on the AMD64 architecture.  A local attacker could use
this flaw to gain privileges. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1144 to this issue.

ISEC security research discovered multiple vulnerabilities in the IGMP
functionality which was backported in the Red Hat Enterprise Linux 3
kernels.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

ISEC security research and Georgi Guninski independantly discovered a flaw
in the scm_send function in the auxiliary message layer.  A local user
could create a carefully crafted auxiliary message which could cause a
denial of service (system hang).  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1016 to this issue.

A floating point information leak was discovered in the ia64 architecture
context switch code.  A local user could use this flaw to read register
values of other processes by setting the MFH bit. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CAN-2004-0565 to this issue.

Kirill Korotaev found a flaw in load_elf_binary affecting kernels prior to
2.4.26.  A local user could create a carefully crafted binary in such a
way that it would cause a denial of service (system crash).  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CAN-2004-1234 to this issue.

These packages also fix issues in the io_edgeport driver, and a memory leak
in ip_options_get.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-12-23" />
        <updated date="2004-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0565.html">CVE-2004-0565</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1016.html">CVE-2004-1016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1017.html">CVE-2004-1017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1137.html">CVE-2004-1137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1144.html">CVE-2004-1144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1234.html">CVE-2004-1234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1335.html">CVE-2004-1335</cve>
                <bugzilla href="http://bugzilla.redhat.com/124734" id="124734">CAN-2004-0565 Information leak on Linux/ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126126" id="126126">CAN-2004-0565 Information leak on Linux/ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142729" id="142729">CAN-2004-1016 CMSG validation checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142748" id="142748">CAN-2004-1137 IGMP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142964" id="142964">CAN-2004-1144 x86-64 privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142965" id="142965">CAN-2004-1234 kernel denial of service vulnerability and exploit</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689014" comment="kernel-source is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689002" comment="kernel is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689016" comment="kernel-doc is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689008" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689012" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689018" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689004" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20040689010" comment="kernel-smp is earlier than 0:2.4.21-27.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050009" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:009: kdelibs, kdebase security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-009.html" />
          <reference source="CVE" ref_id="CVE-2004-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1158.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
          <reference source="CVE" ref_id="CVE-2005-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0078.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.

Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1158
to this issue.

A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-0078 to this issue.

All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1158.html">CVE-2004-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0078.html">CVE-2005-0078</cve>
                <bugzilla href="http://bugzilla.redhat.com/142393" id="142393">CAN-2004-1158 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145381" id="145381">CAN-2005-0078 password bypass in kde screensaver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146760" id="146760">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009002" comment="kdelibs is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009004" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009006" comment="kdebase is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412003" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009008" comment="kdebase-devel is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412005" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050010" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:010: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:010-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-010.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  It is possible
that a malicious user could create a file containing a specially crafted
modeline which could cause arbitrary command execution when viewed by a
victim.  Please note that this issue only affects users who have modelines
and filetype plugins enabled, which is not the default.  The  Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1138
to this issue.

All users of VIM are advised to upgrade to these erratum packages,
which contain a backported patch for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-05" />
        <updated date="2005-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
                <bugzilla href="http://bugzilla.redhat.com/142444" id="142444">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010002" comment="vim is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010004" comment="vim-common is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050011" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:011: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-011.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-02" />
        <updated date="2005-02-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/142952" id="142952">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145481" id="145481">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011002" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050012" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:012: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:012-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-012.html" />
          <reference source="CVE" ref_id="CVE-2004-0971" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0971.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

Additionally a temporary file bug was found in the Kerberos krb5-send-pr
program.  It is possible that an attacker could create a temporary file
that would allow an arbitrary file to be overwritten which the victim has
write access to.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0971 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-19" />
        <updated date="2005-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0971.html">CVE-2004-0971</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/136304" id="136304">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140066" id="140066">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142902" id="142902">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012006" comment="krb5-libs is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012004" comment="krb5-devel is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012008" comment="krb5-server is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012002" comment="krb5 is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012010" comment="krb5-workstation is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050013" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:013: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-013.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package.  An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.

A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.

The lppasswd utility ignores write errors when modifying the CUPS passwd
file.  A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.

In addition to these security issues, two other problems not relating
to security have been fixed:

Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop.  This has been fixed in later
versions of CUPS, and has been backported in these updated packages.

The cancel-cups(1) man page is a symbolic link to another man page.  The
target of this link has been corrected.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
                <bugzilla href="http://bugzilla.redhat.com/136973" id="136973">cancel-cups man page missing from errata package</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143087" id="143087">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143566" id="143566">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013004" comment="cups-devel is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013006" comment="cups-libs is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013002" comment="cups is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050018" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:018: xpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-018.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf packages should upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/143499" id="143499">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018002" comment="xpdf is earlier than 1:2.02-9.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050019" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:019: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-019.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

iDEFENSE has reported an integer overflow bug that affects libtiff. An
attacker who has the ability to trick a user into opening a malicious TIFF
file could cause the application linked to libtiff to crash or possibly
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin reported another integer overflow in the tiffdump 
utility.  An atacker who has the ability to trick a user into opening a
malicious TIFF file with tiffdump could possibly execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/143505" id="143505">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143577" id="143577">CVE-2004-1183 libtiff: tiffdump integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019002" comment="libtiff is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019004" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050021" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:021: kdegraphics security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:021-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-021.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1307.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
    
    <description>The kdegraphics package contains graphics applications for the K Desktop
Environment.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. The kfax application contains a copy of
the libtiff code used for parsing TIFF files and is therefore affected by
these bugs. An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause kfax to crash or possibly execute arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found. The kfax application contains a copy of the libtiff code used
for parsing TIFF files and is therefore affected by these bugs. An attacker
who has the ability to trick a user into opening a malicious TIFF file
could cause kfax to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0803 to this issue.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-14" />
        <updated date="2005-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1307.html">CVE-2004-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
                <bugzilla href="http://bugzilla.redhat.com/135466" id="135466">CAN-2004-0803 buffer overflows in libtiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135470" id="135470">CAN-2004-0886 multiple integer overflows in libtiff</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021002" comment="kdegraphics is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021004" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050025" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:025: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-025.html" />
          <reference source="CVE" ref_id="CVE-2005-0021" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0021.html" />
          <reference source="CVE" ref_id="CVE-2005-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0022.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. 

A buffer overflow was discovered in the spa_base64_to_bits function in
Exim, as originally obtained from Samba code.  If SPA authentication is
enabled, a remote attacker may be able to exploit this vulnerability to
execute arbitrary code as the 'exim' user.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to
this issue.  Please note that SPA authentication is not enabled by default
in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and
dns_build_reverse functions in Exim.  A local user can trigger these flaws
by executing exim with carefully crafted command line arguments and may be
able to gain the privileges of the 'exim' account.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0021.html">CVE-2005-0021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0022.html">CVE-2005-0022</cve>
                <bugzilla href="http://bugzilla.redhat.com/144099" id="144099">CAN-2005-0021 exim security issues (CAN-2005-0022)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025002" comment="exim is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050026" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:026: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:026-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-026.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/144257" id="144257">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145055" id="145055">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026006" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026002" comment="tetex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026012" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026014" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026004" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026008" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026010" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050032" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:032: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:032-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-032.html" />
          <reference source="CVE" ref_id="CVE-2004-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1018.html" />
          <reference source="CVE" ref_id="CVE-2004-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1019.html" />
          <reference source="CVE" ref_id="CVE-2004-1065" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1065.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP. PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow. An attacker could create a carefully crafted image file in such
a way which, if parsed by a PHP script using the exif extension, could
cause a crash or potentially execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions. These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1018.html">CVE-2004-1018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1019.html">CVE-2004-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1065.html">CVE-2004-1065</cve>
                <bugzilla href="http://bugzilla.redhat.com/141136" id="141136">CAN-2004-1018 Multiple issues in PHP (CAN-2004-1019 CAN-2004-1020)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032028" comment="php-gd is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032016" comment="php-odbc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032012" comment="php-mysql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032002" comment="php is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032022" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032024" comment="php-mbstring is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032014" comment="php-pgsql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032004" comment="php-devel is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032026" comment="php-ncurses is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032018" comment="php-snmp is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032008" comment="php-imap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032006" comment="php-pear is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032020" comment="php-domxml is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032010" comment="php-ldap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050033" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:033: alsa-lib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-033.html" />
          <reference source="CVE" ref_id="CVE-2005-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0087.html" />
    
    <description>The alsa-lib package provides a library of functions for communication with
kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack
execution protection to be disabled for the libasound.so library.  
The effect of this flaw is that stack execution protection, through NX or
Exec-Shield, would be disabled for any application linked to libasound. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a
patched version of the library which correctly enables stack execution
protection.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0087.html">CVE-2005-0087</cve>
                <bugzilla href="http://bugzilla.redhat.com/144518" id="144518">CAN-2005-0087 alsa-lib disables stack protection for it's users</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033004" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033005" comment="alsa-lib-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033002" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033003" comment="alsa-lib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050034" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:034: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:034-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-034.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf. An attacker could construct a carefully crafted PDF file that could
cause Xpdf to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org).  Red Hat Enterprise Linux 4 contained a fix for this
issue, but it was found to be incomplete and left 64-bit architectures
vulnerable.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0206 to this issue.

All users of Xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135066" id="135066">PDF is displayed garbled, older xpdf works</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144197" id="144197">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145052" id="145052">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147498" id="147498">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050034002" comment="xpdf is earlier than 1:3.00-11.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050035" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:035: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:035-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-035.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

infamous41md discovered integer overflow flaws in libtiff.  An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to overflow a heap buffer when the
file was opened by a victim.  Due to the nature of the overflow it is
unlikely that it is possible to use this flaw to execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin discovered an integer overflow flaw in libtiff.  An
attacker could create a carefully crafted TIFF file in such a way that it
could cause an application linked with libtiff to crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/144185" id="144185">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144186" id="144186">CAN-2004-1183 libtiff integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035002" comment="libtiff is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035004" comment="libtiff-devel is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040577005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050036" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:036: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-036.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  An attacker
could create a text file containing a specially crafted modeline which
could cause arbitrary command execution when viewed by a victim using VIM. 
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-1138 to this issue.  Please note that this issue only affects
users who have modelines and filetype plugins enabled, which is not the
default.  

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM.  A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue. 

All users of VIM are advised to upgrade to these erratum packages,
which contain backported patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144187" id="144187">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144880" id="144880">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036006" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036002" comment="vim is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036010" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036004" comment="vim-common is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036008" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050037" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:037: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-037.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization.  (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084) 

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/144188" id="144188">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145483" id="145483">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037002" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050038" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:038: mozilla security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:038-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-038.html" />
          <reference source="CVE" ref_id="CVE-2004-1316" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1316.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way
Mozilla handles NNTP URLs.  If a user visits a malicious web page or is
convinced to click on a malicious link, it may be possible for an attacker
to execute arbitrary code on the victim's machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1316.html">CVE-2004-1316</cve>
                <bugzilla href="http://bugzilla.redhat.com/143994" id="143994">CAN-2004-1316 buffer overflow in mozilla</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038002" comment="mozilla is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050039" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:039: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-039.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences. A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document. An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments. These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144683" id="144683">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039002" comment="enscript is earlier than 0:1.6.1-24.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050040" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:040: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:040-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-040.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences.  A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document.  An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments.  These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144686" id="144686">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050040002" comment="enscript is earlier than 0:1.6.1-28.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050043" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:043: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:043-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-043.html" />
          <reference source="CVE" ref_id="CVE-2004-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0791.html" />
          <reference source="CVE" ref_id="CVE-2004-1074" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1074.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2004-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1237.html" />
          <reference source="CVE" ref_id="CVE-2005-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0003.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1235 to
this issue.

A flaw was discovered where an executable could cause a VMA overlap leading
to a crash.  A local user could trigger this flaw by creating a carefully
crafted a.out binary on 32-bit systems or a carefully crafted ELF binary
on Itanium systems.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0003 to this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0001 to this issue. A patch
that coincidentally fixed this issue was committed to the Update 4 kernel
release in December 2004.  Therefore Red Hat Enterprise Linux 3 kernels
provided by RHBA-2004:550 and subsequent updates are not vulnerable to
this issue.

A flaw in the system call filtering code in the audit subsystem included
in Red Hat Enterprise Linux 3 allowed a local user to cause a crash when
auditing was enabled.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1237 to this issue.

Olaf Kirch discovered that the recent security fixes for cmsg_len handling
(CAN-2004-1016) broke 32-bit compatibility on 64-bit platforms such as
AMD64 and Intel EM64T. A patch to correct this issue is included.

A recent Internet Draft by Fernando Gont recommended that ICMP Source
Quench messages be ignored by hosts.  A patch to ignore these messages is
included.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-18" />
        <updated date="2005-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0791.html">CVE-2004-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1074.html">CVE-2004-1074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1237.html">CVE-2004-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0003.html">CVE-2005-0003</cve>
                <bugzilla href="http://bugzilla.redhat.com/132245" id="132245">CAN-2004-1237 Kernel panic when stopping Lotus Domino 6.52</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141996" id="141996">CAN-2004-1237 instant kernel panic from one line perl program - BAD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142091" id="142091">CAN-2004-1237 kernel oops captured, system hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142442" id="142442">CAN-2004-1237 kernel panic ( __audit_get_target)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143866" id="143866">CAN-2004-1237 kernel panic caused by auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144048" id="144048">CAN-2004-1237 kernel panic when Oracle agentctl is run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144134" id="144134">CAN-2004-1235 isec.pl uselib() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144784" id="144784">CAN-2005-0003 huge vma-in-executable bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043004" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043002" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043006" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043018" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043014" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043012" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050045" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:045: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-045.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/144196" id="144196">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045006" comment="krb5-libs is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045004" comment="krb5-devel is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045008" comment="krb5-server is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045002" comment="krb5 is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045010" comment="krb5-workstation is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050049" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:049: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:049-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-049.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit these buffer overflow
vulnerabilities on x86 architectures.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145102" id="145102">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049004" comment="cups-devel is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049006" comment="cups-libs is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049002" comment="cups is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050053" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:053: CUPS security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:053-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-053.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects CUPS due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause CUPS to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects the CUPS pdftops filter due to a shared codebase.  An attacker
who has the ability to send a malicious PDF file to a printer could
possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the ParseCommand function in the
hpgltops program. An attacker who has the ability to send a malicious HPGL
file to a printer could possibly execute arbitrary code as the "lp" user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1267 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

The lppasswd utility was found to ignore write errors when modifying the
CUPS passwd file. A local user who is able to fill the associated file
system could corrupt the CUPS password file or prevent future uses of
lppasswd. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility was found to not verify that the passwd.new file is
different from STDERR, which could allow local users to control output to
passwd.new via certain user input that triggers an error message. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1270 to this issue.

All users of cups should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144191" id="144191">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144194" id="144194">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145088" id="145088">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147480" id="147480">CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053002" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050057" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:057: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:057-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-057.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files for GNOME. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

Users should update to this erratum package which contains backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144210" id="144210">CAN-2004-1125 gpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145054" id="145054">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147518" id="147518">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057002" comment="gpdf is earlier than 0:2.8.2-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050059" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:059: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-059.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found when processing the /Encrypt /Length tag.
An attacker could construct a carefully crafted PDF file that could cause
Xpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf package should upgrade to this updated package,
which resolves this issue</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145049" id="145049">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050059002" comment="xpdf is earlier than 1:2.02-9.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050060" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:060: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-060.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious webpage
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious Web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious Web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145545" id="145545">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146161" id="146161">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146779" id="146779">CAN-2005-0211 Buffer overflow in WCCP recvfrom() call</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146785" id="146785">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050061" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:061: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:061-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-061.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious web page
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-11" />
        <updated date="2005-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145540" id="145540">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146159" id="146159">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146780" id="146780">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050061002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050065" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:065: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:065-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-065.html" />
          <reference source="CVE" ref_id="CVE-2004-1145" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1145.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in
the Konqueror web browser. If a user has Java enabled in Konqueror and
visits a malicious website, the website could run a carefully crafted
Java-applet and obtain escalated privileges allowing reading and writing of
arbitrary files with the privileges of the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave.  KDE applications such as
Konqueror could be forced to execute arbitrary FTP commands via a carefully
crafted ftp URL.  The URL could also be crafted in such a way as to send an
arbitrary email via SMTP.  An attacker could make use of this flaw if a
victim visits a malicious web site. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1145.html">CVE-2004-1145</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
                <bugzilla href="http://bugzilla.redhat.com/144211" id="144211">CAN-2004-1145 Konqueror Java Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145938" id="145938">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065002" comment="kdelibs is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065004" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050066" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:066: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-066.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that
also affects kpdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects kpdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf which also affects
kpdf due to a shared codebase. An attacker could construct a carefully
crafted PDF file that could cause kpdf to crash or possibly execute
arbitrary code when opened. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/144231" id="144231">CAN-2004-1125 kpdf buffer overflows (CAN-2005-0064)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147517" id="147517">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066002" comment="kdegraphics is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050068" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:068: less security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:068-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-068.html" />
          <reference source="CVE" ref_id="CVE-2005-0086" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0086.html" />
    
    <description>The less utility is a text file browser that resembles more, but has
extended capabilities.

Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue.  Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit this vulnerability on x86
architectures.

All users of the less package should upgrade to this updated package,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0086.html">CVE-2005-0086</cve>
                <bugzilla href="http://bugzilla.redhat.com/145527" id="145527">CAN-2005-0086 less crashes on scrolling of binary files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068002" comment="less is earlier than 0:378-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068003" comment="less is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050069" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:069: perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:069-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-069.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069002" comment="perl-DBI is earlier than 0:1.32-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050070" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:070: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:070-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-070.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
          <reference source="CVE" ref_id="CVE-2005-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0759.html" />
          <reference source="CVE" ref_id="CVE-2005-0760" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0760.html" />
          <reference source="CVE" ref_id="CVE-2005-0761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0761.html" />
          <reference source="CVE" ref_id="CVE-2005-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0762.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible
that a TIFF image file with an invalid tag could cause ImageMagick to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a
specially crafted TIFF image file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible
that a specially crafted PSD file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser.  It is possible
that an attacker could execute arbitrary code by tricking a user into
opening a specially crafted SGI image file. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0759.html">CVE-2005-0759</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0760.html">CVE-2005-0760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0761.html">CVE-2005-0761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0762.html">CVE-2005-0762</cve>
                <bugzilla href="http://bugzilla.redhat.com/145111" id="145111">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150312" id="150312">CAN-2005-0759 Denial of Service in .tiff images with invalid TAG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150315" id="150315">CAN-2005-0760 Accessing memory outside of image during decoding of TIFF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150323" id="150323">CAN-2005-0761 Bug in parsing PSD files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150327" id="150327">CAN-2005-0762 Buffer overflow in SGI parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070004" comment="ImageMagick-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070006" comment="ImageMagick-perl is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070002" comment="ImageMagick is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070008" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050071" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:071: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:071-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-071.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/145123" id="145123">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071002" comment="ImageMagick is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050072" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:072: perl-DBI security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:072-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-072.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050072002" comment="perl-DBI is earlier than 0:1.40-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050073" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:073: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:073-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-073.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive.  

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option.  This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

Users of cpio should upgrade to this updated package, which resolves
this issue.

Red Hat would like to thank Mike O'Connor for bringing this issue to our
attention.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/145725" id="145725">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073002" comment="cpio is earlier than 0:2.5-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050074" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:074: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:074-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-074.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory.  This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rexec command failed with "Invalid Argument", because the code
used sigaction() as an unsupported signal.

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

The rexec command prompted for username and password regardless of the
~/.netrc configuration file contents. This updated package contains a patch
that no longer skips the ~/.netrc file. 

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/67361" id="67361">rcp gives incorrect error report when file system writes fai</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118630" id="118630">rexec fails with "Invalid Argument"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146435" id="146435">RHEL3: rexec prompts for username/password before checking ~/.netrc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146437" id="146437">RHEL3: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146464" id="146464">malicious rsh server can cause rcp to write to arbitrary files (like scp CAN-2004-0175)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074002" comment="rsh is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074004" comment="rsh-server is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050080" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:080: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:080-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-080.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option. This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

All users of cpio should upgrade to this updated package, which resolves
this issue, and adds support for large files (> 2GB).</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145720" id="145720">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050080002" comment="cpio is earlier than 0:2.5-3e.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050081" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:081: ghostscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:081-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-081.html" />
          <reference source="CVE" ref_id="CVE-2004-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0967.html" />
    
    <description>Ghostscript is a program for displaying PostScript files or printing them
to non-PostScript printers.

A bug was found in the way several of Ghostscript's utility scripts created
temporary files. A local user could cause these utilities to overwrite
files that the victim running the utility has write access to.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2004-0967 to
this issue.

Additionally, this update addresses the following issue:

A problem has been identified in the PDF output driver, which can cause
output to be delayed indefinitely on some systems.  The fix has been
backported from GhostScript 7.07.

All users of ghostscript should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0967.html">CVE-2004-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/97583" id="97583">[7.05-20.1] gs gets stuck reading /dev/random</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136321" id="136321">CAN-2004-0967 temporary file vulnerabilities in various ghostscript scripts.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081002" comment="ghostscript is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081003" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081004" comment="ghostscript-devel is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081005" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081006" comment="hpijs is earlier than 0:1.3-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081007" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050090" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:090: htdig security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-090.html" />
          <reference source="CVE" ref_id="CVE-2005-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0085.html" />
    
    <description>The ht://Dig system is a Web search and indexing system for a small domain
or intranet.

Michael Krax reported a cross-site scripting bug affecting htdig. An
attacker could construct a carefully crafted URL which can cause a web
browser to execute malicious script once visited.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-0085
to this issue.

Users of htdig should upgrade to these updated packages, which contain a
backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0085.html">CVE-2005-0085</cve>
                <bugzilla href="http://bugzilla.redhat.com/144261" id="144261">CAN-2005-0085 XSS vulnerability in htdig 3.2.0b6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145649" id="145649">htdig packaging cleanups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090002" comment="htdig is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090003" comment="htdig is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090004" comment="htdig-web is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090005" comment="htdig-web is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050092" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:092: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:092-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-092.html" />
          <reference source="CVE" ref_id="CVE-2004-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1056.html" />
          <reference source="CVE" ref_id="CVE-2004-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1137.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2005-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0001.html" />
          <reference source="CVE" ref_id="CVE-2005-0090" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0090.html" />
          <reference source="CVE" ref_id="CVE-2005-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0091.html" />
          <reference source="CVE" ref_id="CVE-2005-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0092.html" />
          <reference source="CVE" ref_id="CVE-2005-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0176.html" />
          <reference source="CVE" ref_id="CVE-2005-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0177.html" />
          <reference source="CVE" ref_id="CVE-2005-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0178.html" />
          <reference source="CVE" ref_id="CVE-2005-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0179.html" />
          <reference source="CVE" ref_id="CVE-2005-0180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0180.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered multiple vulnerabilities in the IGMP
functionality.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  (CAN-2005-0001)

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  (CAN-2004-1235)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architecture was discovered.  A local user could use this flaw to write to
privileged IO ports.  (CAN-2005-0204)

The Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not
properly check the DMA lock, which could allow remote attackers or local
users to cause a denial of service (X Server crash) or possibly modify the
video output. (CAN-2004-1056)

OGAWA Hirofumi discovered incorrect tables sizes being used in the
filesystem Native Language Support ASCII translation table.  This could
lead to a denial of service (system crash).  (CAN-2005-0177)

Michael Kerrisk discovered a flaw in the 2.6.9 kernel which allows users to
unlock arbitrary shared memory segments.  This flaw could lead to
applications not behaving as expected.  (CAN-2005-0176)

Improvements in the POSIX signal and tty standards compliance exposed
a race condition.  This flaw can be triggered accidentally by threaded
applications or deliberately by a malicious user and can result in a
denial of service (crash) or in occasional cases give access to a small
random chunk of kernel memory.  (CAN-2005-0178)

The PaX team discovered a flaw in mlockall introduced in the 2.6.9 kernel.
An unprivileged user could use this flaw to cause a denial of service
(CPU and memory consumption or crash).  (CAN-2005-0179)

Brad Spengler discovered multiple flaws in sg_scsi_ioctl in the 2.6 kernel.
An unprivileged user may be able to use this flaw to cause a denial of
service (crash) or possibly other actions.  (CAN-2005-0180)

Kirill Korotaev discovered a missing access check regression in the Red Hat
Enterprise Linux 4 kernel 4GB/4GB split patch.  On systems using the
hugemem kernel, a local unprivileged user could use this flaw to cause a
denial of service (crash).  (CAN-2005-0090)

A flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch can
allow syscalls to read and write arbitrary kernel memory.  On systems using
the hugemem kernel, a local unprivileged user could use this flaw to gain
privileges.  (CAN-2005-0091)

An additional flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split
patch was discovered. On x86 systems using the hugemem kernel, a local
unprivileged user may be able to use this flaw to cause a denial of service
(crash).  (CAN-2005-0092)

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1056.html">CVE-2004-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1137.html">CVE-2004-1137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0001.html">CVE-2005-0001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0090.html">CVE-2005-0090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0091.html">CVE-2005-0091</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0092.html">CVE-2005-0092</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0176.html">CVE-2005-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0177.html">CVE-2005-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0178.html">CVE-2005-0178</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0179.html">CVE-2005-0179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0180.html">CVE-2005-0180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
                <bugzilla href="http://bugzilla.redhat.com/142670" id="142670">CAN-2004-1137 IGMP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144131" id="144131">CAN-2005-0090 4GB split DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144136" id="144136">CAN-2004-1235 isec.pl do_brk() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144391" id="144391">CAN-2004-1056 insufficient locking checks in DRM code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144412" id="144412">CAN-2005-0001 page fault @ SMP privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144471" id="144471">CAN-2005-0176 unlock someone elses ipc memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144522" id="144522">CAN-2005-0180 2.6 scsi ioctl integer overflow and information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144528" id="144528">CAN-2005-0179 RLIMIT_MEMLOCK bypass and (2.6) unprivileged user DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144532" id="144532">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144658" id="144658">CAN-2005-0091 4g4g PROT_NONE fix (CAN-2005-0092)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146083" id="146083">20041212 Clear ebp on sysenter return</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146095" id="146095">CAN-2005-0177 nls_ascii incorrect table size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146101" id="146101">CAN-2005-0178 tty/setsid race</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092002" comment="kernel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092006" comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092004" comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092008" comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050094" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:094: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:094-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-094.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
    
    <description>Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victim's
clipboard. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0146 to this issue.

A bug was found in the way Thunderbird handled cookies when loading content
over HTTP regardless of the user's preference. It is possible that a
particular user could be tracked through the use of malicious mail messages
which load content over HTTP. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0149 to this issue.

Users of Thunderbird are advised to upgrade to this updated package,
which contains Thunderbird version 1.0 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
                <bugzilla href="http://bugzilla.redhat.com/146315" id="146315">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156749" id="156749">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094002" comment="thunderbird is earlier than 0:1.0-1.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050099" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:099: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:099-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-099.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145387" id="145387">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145967" id="145967">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050100" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:100: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-100.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146657" id="146657">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050100002" comment="mod_python is earlier than 0:3.1.3-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050102" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:102: dbus security update. (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-102.html" />
          <reference source="CVE" ref_id="CVE-2005-0201" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0201.html" />
    
    <description>D-BUS is a system for sending messages between applications. It is
used both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Dan Reed discovered that a user can send and listen to messages on another
user's per-user session bus if they know the address of the socket. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0201 to this issue.  In Red Hat Enterprise Linux 4, the
per-user session bus is only used for printing notifications,  therefore
this issue would only allow a local user to examine or send additional
print notification messages.

Users of dbus are advised to upgrade to these updated packages,
which contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0201.html">CVE-2005-0201</cve>
                <bugzilla href="http://bugzilla.redhat.com/146766" id="146766">CAN-2005-0201 dbus information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102008" comment="dbus-x11 is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102009" comment="dbus-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102010" comment="dbus-python is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102011" comment="dbus-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102004" comment="dbus-devel is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102005" comment="dbus-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102002" comment="dbus is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102003" comment="dbus is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102006" comment="dbus-glib is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102007" comment="dbus-glib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050103" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:103: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-103.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

An unsafe file permission bug was discovered in the rmtree() function in
the File::Path module.  The rmtree() function removes files and directories
in an insecure manner, which could allow a local user to read or delete
arbitrary files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0452 to this issue.

Users of Perl are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/146739" id="146739">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156 )</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146774" id="146774">CAN-2004-0452 File::Path::rmtree() issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103004" comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103002" comment="perl is earlier than 3:5.8.5-12.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050104" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:104: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-104.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146655" id="146655">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050104002" comment="mod_python is earlier than 0:3.0.3-5.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040058003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050105" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:105: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-105.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-07" />
        <updated date="2005-02-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/140227" id="140227">Potential insecurity in CGI.pm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146737" id="146737">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105006" comment="perl-CGI is earlier than 2:2.81-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105008" comment="perl-DB_File is earlier than 2:1.804-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105010" comment="perl-suidperl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105004" comment="perl-CPAN is earlier than 2:1.61-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105002" comment="perl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050106" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:106: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-106.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH
replaces rlogin and rsh, and provides secure encrypted communications
between two untrusted hosts over an insecure network. X11 connections and
arbitrary TCP/IP ports can also be forwarded over a secure channel. Public
key authentication can be used for "passwordless" access to servers.

The scp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses scp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also correct the following bugs:

On systems where direct ssh access for the root user was disabled by
configuration (setting "PermitRootLogin no"), attempts to guess the root
password could be judged as sucessful or unsucessful by observing a delay.

On systems where the privilege separation feature was turned on, the user
resource limits were not correctly set if the configuration specified to
raise them above the defaults.  It was also not possible to change an
expired password.

Users of openssh should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/120147" id="120147">CAN-2004-0175 malicious ssh server can cause scp to write to arbitrary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124602" id="124602">OpenSSH does not allow users to change expired passwords when privsep is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141642" id="141642">SSH allows attacker to divine root password</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106002" comment="openssh is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050108" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:108: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:108-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-108.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146649" id="146649">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108004" comment="python-devel is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108008" comment="python-docs is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108010" comment="tkinter is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108002" comment="python is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108006" comment="python-tools is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050109" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:109: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-109.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146645" id="146645">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109004" comment="python-devel is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109008" comment="python-docs is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109010" comment="tkinter is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109002" comment="python is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109006" comment="python-tools is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050110" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:110: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-110.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running emacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146702" id="146702">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110008" comment="emacs-el is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110010" comment="emacs-leim is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110002" comment="emacs is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110006" comment="emacs-common is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110007" comment="emacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110004" comment="emacs-nox is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110005" comment="emacs-nox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050112" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:112: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:112-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-112.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running emacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146700" id="146700">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112004" comment="emacs-el is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112006" comment="emacs-leim is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112002" comment="emacs is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050122" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:122: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:122-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-122.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM. A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue.

All users of VIM are advised to upgrade to these erratum packages, which
contain a backported patche for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144695" id="144695">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122002" comment="vim is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122004" comment="vim-common is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050128" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:128: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:128-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-128.html" />
          <reference source="CVE" ref_id="CVE-2005-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0198.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access
protocols.

A logic error in the CRAM-MD5 code in the University of Washington IMAP
(UW-IMAP) server was discovered.  When Challenge-Response Authentication
Mechanism with MD5 (CRAM-MD5) is enabled, UW-IMAP does not properly enforce
all the required conditions for successful authentication, which could
allow remote attackers to authenticate as arbitrary users.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
 CAN-2005-0198 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-23" />
        <updated date="2005-02-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0198.html">CVE-2005-0198</cve>
                <bugzilla href="http://bugzilla.redhat.com/145469" id="145469">CAN-2005-0198 user validation issue in imap when using CRAM-MD5 authetication</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128006" comment="imap-utils is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128004" comment="imap-devel is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128002" comment="imap is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050132" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:132: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-132.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect Xpdf.  CUPS contained a copy of the Xpdf code
used for parsing PDF files and was therefore affected by these bugs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2004-0888 to this issue, and Red Hat released erratum
RHSA-2004:543 with updated packages.

It was found that the patch used to correct this issue was not sufficient
and did not fully protect CUPS running on 64-bit architectures.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue. 

These updated packages also include a fix that prevents the CUPS
initscript from being accidentally replaced.

All users of CUPS on 64-bit architectures should upgrade to these updated
packages, which contain a corrected patch and are not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135378" id="135378">CAN-2004-0888 xpdf issues affect cups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132004" comment="cups-devel is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132006" comment="cups-libs is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132002" comment="cups is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040449003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050133" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:133: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:133-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-133.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running xemacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146706" id="146706">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133004" comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133005" comment="xemacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133010" comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133008" comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133006" comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133007" comment="xemacs-nox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133002" comment="xemacs is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050134" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:134: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:134-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-134.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running xemacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146704" id="146704">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134006" comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134004" comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134002" comment="xemacs is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050135" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:135: squirrelmail security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:135-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-135.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145384" id="145384">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145964" id="145964">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050135002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040240003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050136" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:136: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:136-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-136.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>The mailman package is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147342" id="147342">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136002" comment="mailman is earlier than 3:2.1.5-24.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050137" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:137: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:137-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-137.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>Mailman is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.  

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of Mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147344" id="147344">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050137002" comment="mailman is earlier than 3:2.1.5-31.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050138" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:138: postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:138-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-138.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>A flaw in the LOAD command in PostgreSQL was discovered. A local user
could use this flaw to load arbitrary shared libraries and therefore
execute arbitrary code, gaining the privileges of the PostgreSQL server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered. A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL. A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found. A user could create carefully crafted arrays and cause a denial of
service (crash). The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

The update also fixes some minor problems, notably conflicts with SELinux.

Users of postgresql should update to these erratum packages that contain
patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147380" id="147380">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138020" comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138008" comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138012" comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138022" comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138010" comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138004" comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138016" comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138002" comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138018" comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138014" comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138006" comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050141" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:141: rh-postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:141-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-141.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw in the LOAD command in PostgreSQL was discovered.  A local user
could use this flaw to load arbitrary shared librarys and therefore execute
arbitrary code, gaining the privileges of the PostgreSQL server.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered.  A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL.  A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found.  A user could create carefully crafted arrays and cause a denial of
service (crash).  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

Users of PostgreSQL are advised to update to these erratum packages which
are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147442" id="147442">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141020" comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141008" comment="rh-postgresql-docs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141010" comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141002" comment="rh-postgresql is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141018" comment="rh-postgresql-python is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141014" comment="rh-postgresql-pl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141012" comment="rh-postgresql-devel is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141022" comment="rh-postgresql-test is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141016" comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141006" comment="rh-postgresql-server is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141004" comment="rh-postgresql-libs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040489005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050152" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:152: postfix security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-152.html" />
          <reference source="CVE" ref_id="CVE-2005-0337" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0337.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the ipv6 patch used with Postfix.  When the file
/proc/net/if_inet6 is not available and permit_mx_backup is enabled in
smtpd_recipient_restrictions, this flaw could allow remote attackers to
bypass e-mail restrictions and perform mail relaying by sending mail to an
IPv6 hostname.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0337 to this issue.

These updated packages also fix the following problems:

- wrong permissions on doc directory
- segfault when gethostbyname or gethostbyaddr fails

All users of postfix should upgrade to these updated packages, which
contain patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0337.html">CVE-2005-0337</cve>
                <bugzilla href="http://bugzilla.redhat.com/139983" id="139983">newaliases segfaults when gethostbyname or gethostbyaddr fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146732" id="146732">CAN-2005-0337 open relay bug in postfix ipv6 patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147280" id="147280">Permissions on doc directory is wrong</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152004" comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152005" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152002" comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152003" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050165" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:165: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-165.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/146978" id="146978">RHEL4: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146979" id="146979">RHEL4: rcp gives incorrect error report when file system writes fai</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165002" comment="rsh is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165004" comment="rsh-server is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050173" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:173: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:173-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-173.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles FQDN lookups.  It was possible  
to crash the Squid server by sending a carefully crafted DNS response to  
an FQDN lookup.  The Common Vulnerabilities and Exposures project  
(cve.mitre.org) has assigned the name CAN-2005-0446 to this issue.  
  
Users of squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050173002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050175" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:175: kdenetwork security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:175-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-175.html" />
          <reference source="CVE" ref_id="CVE-2005-0205" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0205.html" />
    
    <description>The kdenetwork packages contain a collection of networking applications for
the K Desktop Environment.

A bug was found in the way kppp handles privileged file descriptors.  A
malicious local user could make use of this flaw to modify the /etc/hosts
or /etc/resolv.conf files, which could be used to spoof domain information. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0205 to this issue.

Please note that the default installation of kppp on Red Hat Enterprise
Linux uses consolehelper and is not vulnerable to this issue.  However, the
kppp FAQ provides instructions for removing consolehelper and running kppp
suid root, which is a vulnerable configuration.

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0205.html">CVE-2005-0205</cve>
                <bugzilla href="http://bugzilla.redhat.com/148912" id="148912">CAN-2005-0205 kppp local domain name hijacking</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175002" comment="kdenetwork is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175004" comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050176" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:176: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-176.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0589.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0592.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the Firefox string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

A bug was found in the way Firefox handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Firefox allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527).

A flaw was found in the way Firefox displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Firefox handles plug-in temporary files. A
malicious local user could create a symlink to a victims directory, causing
it to be deleted when the victim exits Firefox. (CAN-2005-0578)

A bug has been found in one of Firefox's UTF-8 converters. It may be
possible for an attacker to supply a specially crafted UTF-8 string to the
buggy converter, leading to arbitrary code execution. (CAN-2005-0592)

A bug was found in the Firefox javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Firefox displays the HTTP authentication prompt.
When a user is prompted for authentication, the dialog window is displayed
over the active tab, regardless of the tab that caused the pop-up to appear
and could trick a user into entering their username and password for a
trusted site.  (CAN-2005-0584)

A bug was found in the way Firefox displays the save file dialog. It is
possible for a malicious webserver to spoof the Content-Disposition header,
tricking the user into thinking they are downloading a different filetype.
(CAN-2005-0586)

A bug was found in the way Firefox handles users "down-arrow" through auto
completed choices. When an autocomplete choice is selected, the information
is copied into the input control, possibly allowing a malicious web site to
steal information by tricking a user into arrowing through autocompletion
choices. (CAN-2005-0589)

Several bugs were found in the way Firefox displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0593)

A bug was found in the way Firefox displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

A bug was found in the way Firefox handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

A bug was found in the way Firefox displays the installation confirmation
dialog. An attacker could add a long user:pass before the true hostname,
tricking a user into thinking they were installing content from a trusted
source. (CAN-2005-0590)

A bug was found in the way Firefox displays download and security dialogs.
An attacker could cover up part of a dialog window tricking the user into
clicking "Allow" or "Open", which could potentially lead to arbitrary code
execution. (CAN-2005-0591)

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-01" />
        <updated date="2005-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0589.html">CVE-2005-0589</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0592.html">CVE-2005-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/142506" id="142506">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144216" id="144216">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147402" id="147402">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147727" id="147727">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147735" id="147735">CAN-2005-0231 firefox javascript tab security bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149876" id="149876">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149923" id="149923">CAN-2005-0578 Unsafe /tmp/plugtmp directory exploitable to erase user's files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149929" id="149929">CAN-2005-0584 HTTP auth prompt tab spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149930" id="149930">CAN-2005-0586 Download dialog spoofing using Content-Disposition header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149931" id="149931">CAN-2005-0588 XSLT can include stylesheets from arbitrary hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149934" id="149934">CAN-2005-0589 Autocomplete data leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149936" id="149936">CAN-2005-0590 Install source spoofing with user:pass@host</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149937" id="149937">CAN-2005-0591 Spoofing download and security dialogs with overlapping windows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149938" id="149938">CAN-2005-0592 Heap overflow possible in UTF8 to Unicode conversion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149939" id="149939">CAN-2005-0593 SSL "secure site" indicator spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176002" comment="firefox is earlier than 0:1.0.1-1.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050198" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:198: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:198-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-198.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>X.Org X11 is the X Window System which provides the core functionality
of the Linux GUI desktop.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
carefully crafted XPM file in such a way that it could cause an application
linked with libXpm to execute arbitrary code when the file was opened by a
victim. The Common Vulnerabilities and Exposures project  (cve.mitre.org)
has assigned the name CAN-2005-0605 to this issue. 

Since the initial release of Red Hat Enterprise Linux 4, a number of issues
have been addressed in the X.Org X11 X Window System.  This erratum also
updates X11R6.8 to the latest stable point release (6.8.2), which includes
various stability and reliability fixes including (but not limited to) the
following:

- The 'radeon' driver has been modified to disable "RENDER" acceleration
  by default, due to a bug in the implementation which has not yet
  been isolated.  This can be manually re-enabled by using the
  following option in the device section of the X server config file:

    Option "RenderAccel"

- The 'vmware' video driver is now available on 64-bit AMD64 and
  compatible systems.

- The Intel 'i810' video driver is now available on 64-bit EM64T
  systems.

- Stability fixes in the X Server's PCI handling layer for 64-bit systems,
  which resolve some issues reported by "vesa" and "nv" driver users.

- Support for Hewlett Packard's Itanium ZX2 chipset.

- Nvidia "nv" video driver update provides support for some of
  the newer Nvidia chipsets, as well as many stability and reliability
  fixes.

- Intel i810 video driver stability update, which fixes the widely
  reported i810/i815 screen refresh issues many have experienced.

- Packaging fixes for multilib systems, which permit both 32-bit
  and 64-bit X11 development environments to be simultaneously installed
  without file conflicts.

In addition to the above highlights, the X.Org X11 6.8.2 release has a
large number of additional stability fixes which resolve various other
issues reported since the initial release of Red Hat Enterprise Linux 4. 

All users of X11 should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/136941" id="136941">font corruption on openoffice.org menus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143910" id="143910">X is unusable on GeForce 6600GT with nForce4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150036" id="150036">CAN-2005-0605 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157962" id="157962">xorg-x11-6.8.1-23 missing half of Lucida fonts</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198024" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198022" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198030" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198034" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198032" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198028" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198062" comment="fonts-xorg-ISO8859-15-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198063" comment="fonts-xorg-ISO8859-15-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198042" comment="fonts-xorg-truetype is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198043" comment="fonts-xorg-truetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198040" comment="fonts-xorg-base is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198041" comment="fonts-xorg-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198052" comment="fonts-xorg-ISO8859-2-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198053" comment="fonts-xorg-ISO8859-2-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198060" comment="fonts-xorg-ISO8859-14-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198061" comment="fonts-xorg-ISO8859-14-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198054" comment="fonts-xorg-ISO8859-9-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198055" comment="fonts-xorg-ISO8859-9-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198044" comment="fonts-xorg-syriac is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198045" comment="fonts-xorg-syriac is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198064" comment="fonts-xorg-ISO8859-15-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198065" comment="fonts-xorg-ISO8859-15-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198046" comment="fonts-xorg-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198047" comment="fonts-xorg-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198050" comment="fonts-xorg-ISO8859-2-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198051" comment="fonts-xorg-ISO8859-2-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198048" comment="fonts-xorg-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198049" comment="fonts-xorg-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198066" comment="fonts-xorg-cyrillic is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198067" comment="fonts-xorg-cyrillic is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198058" comment="fonts-xorg-ISO8859-14-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198059" comment="fonts-xorg-ISO8859-14-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198056" comment="fonts-xorg-ISO8859-9-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198057" comment="fonts-xorg-ISO8859-9-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198038" comment="fonts-xorg is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198039" comment="fonts-xorg is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050201" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:201: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:201-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-201.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles fully qualified domain name (FQDN)
lookups.  A malicious DNS server could crash Squid by sending a carefully
crafted DNS response to an FQDN lookup.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0446 to
this issue.  
 
This erratum also includes two minor patches to the LDAP helpers.  One 
corrects a slight malformation in ldap search requests (although all 
known LDAP servers accept the requests).  The other adds documentation 
for the -v option to the ldap helpers. 
 
Users of Squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050201002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040133003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050213" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:213: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:213-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-213.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). RHSA-2004:592 contained a fix for this issue, but it was
found to be incomplete and left 64-bit architectures vulnerable. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue.

All users of xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135393" id="135393">CAN-2004-0888 xpdf integer overflows (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050213002" comment="xpdf is earlier than 1:2.02-9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040592003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050215" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:215: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:215-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-215.html" />
          <reference source="CVE" ref_id="CVE-2005-0208" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0208.html" />
          <reference source="CVE" ref_id="CVE-2005-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0472.html" />
          <reference source="CVE" ref_id="CVE-2005-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0473.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

Two HTML parsing bugs were discovered in Gaim. It is possible that a remote
attacker could send a specially crafted message to a Gaim client, causing
it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0208 and CAN-2005-0473 to
these issues.

A bug in the way Gaim processes SNAC packets was discovered.  It is
possible that a remote attacker could send a specially crafted SNAC packet
to a Gaim client, causing the client to stop responding.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0472 to this issue.

Additionally, various client crashes, memory leaks, and protocol issues
have been resolved.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.1.4 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-10" />
        <updated date="2005-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0208.html">CVE-2005-0208</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0472.html">CVE-2005-0472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0473.html">CVE-2005-0473</cve>
                <bugzilla href="http://bugzilla.redhat.com/149273" id="149273">CAN-2005-0472 Gaim DoS issues (CAN-2005-0473)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149533" id="149533">CAN-2005-0208 Gaim HTML parsing DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215002" comment="gaim is earlier than 1:1.1.4-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215005" comment="gaim is earlier than 1:1.1.4-1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050232" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:232: ipsec-tools security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:232-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-232.html" />
          <reference source="CVE" ref_id="CVE-2005-0398" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0398.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel. The ipsec-tools package includes:

- setkey, a program to directly manipulate policies and SAs
- racoon, an IKEv1 keying daemon

A bug was found in the way the racoon daemon handled incoming ISAKMP
requests.  It is possible that an attacker could crash the racoon daemon by
sending a specially crafted ISAKMP packet.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0398 to
this issue. 

Additionally, the following issues have been fixed:
- racoon mishandled restarts in the presence of stale administration sockets.
- on Red Hat Enterprise Linux 4, racoon and setkey did not properly set up
  forward policies, which prevented tunnels from working.

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0398.html">CVE-2005-0398</cve>
                <bugzilla href="http://bugzilla.redhat.com/145531" id="145531">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145535" id="145535">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148950" id="148950">racoon unable to start with stale socket /tmp/.racoon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150179" id="150179">ipsec/racoon/setkey does not properly forward packets to vpn peer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232002" comment="ipsec-tools is earlier than 0:0.2.5-0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232005" comment="ipsec-tools is earlier than 0:0.3.3-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040165003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050235" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:235: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:235-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-235.html" />
          <reference source="CVE" ref_id="CVE-2004-1177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1177.html" />
    
    <description>Mailman manages electronic mail discussion and e-newsletter lists. 

A cross-site scripting (XSS) flaw in the driver script of mailman prior to
version 2.1.5 could allow remote attackers to execute scripts as other web
users. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1177 to this issue.

Users of mailman should update to this erratum package, which corrects this
issue by turning on STEALTH_MODE by default and using Utils.websafe() to
quote the html.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1177.html">CVE-2004-1177</cve>
                <bugzilla href="http://bugzilla.redhat.com/132750" id="132750">Mailman doesn't work with courier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142605" id="142605">init script doesn't use /var/lock/subsys</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143008" id="143008">mailman logrotate has wrong location for mailmanctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147833" id="147833">CAN-2004-1177 - mailman</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235002" comment="mailman is earlier than 3:2.1.5-25.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235005" comment="mailman is earlier than 3:2.1.5-33.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050238" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:238: evolution security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-238.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools. Evolution includes a mailer, calendar, contact manager, and
communication facility.  The tools which make up Evolution are tightly
integrated with one another and act as a seamless personal information
management tool.

A bug was found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default. Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

Additionally, these updated packages address the following issues:

-- If evolution ran during a GNOME session, the evolution-wombat process 
   did not exit when the user logged out of the desktop.

-- For folders marked for Offline Synchronization: if a user moved a
   message from a Local Folder to an IMAP folder while in
   Offline mode, the message was not present in either folder after
   returning to Online mode.
 
   This update fixes this problem. Email messages that have been lost 
   this way may still be present in the following path: 

   ~/evolution/&amp;lt;NAME_OF_MAIL_STORE&amp;gt;/ \
   &amp;lt;path-to-folder-via-subfolder-directories&amp;gt;/ \
   &amp;lt;temporary-uid-of-message&amp;gt;

If this bug has affected you it may be possible to recover data by
examining the contents of this directory.

All users of evolution should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
                <bugzilla href="http://bugzilla.redhat.com/125528" id="125528">Moving to IMAP folder while offline eats mail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155376" id="155376">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157352" id="157352">.ics import crashes Evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157354" id="157354">Creating a meeting crashes evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157355" id="157355">Cannot create all day event in calendar</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238002" comment="evolution is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238004" comment="evolution-devel is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050256" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:256: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-256.html" />
          <reference source="CVE" ref_id="CVE-2004-1453" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1453.html" />
    
    <description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

It was discovered that the use of LD_DEBUG, LD_SHOW_AUXV, and
LD_DYNAMIC_WEAK were not restricted for a setuid program. A local user
could utilize this flaw to gain information, such as the list of symbols
used by the program. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1453 to this issue.

This erratum addresses the following bugs in the GNU C Library:

- fix stack alignment in IA-32 clone
- fix double free in globfree
- fix fnmatch to avoid jumping based on unitialized memory read
- fix fseekpos after ungetc
- fix TZ env var handling if the variable ends with + or -
- avoid depending on values read from unitialized memory in strtold
  on certain architectures
- fix mapping alignment computation in dl-load
- fix i486+ strncat inline assembly
- make gethostid/sethostid work on bi-arch platforms
- fix ppc64 getcontext/swapcontext
- fix pthread_exit if called after pthread_create, but before the created
  thread actually started
- fix return values for tgamma (+-0)
- fix handling of very long lines in /etc/hosts
- avoid page aliasing of thread stacks on AMD64
- avoid busy loop in malloc if concurrent with fork
- allow putenv and setenv in shared library constructors
- fix restoring of CCR in swapcontext and getcontext on ppc64
- avoid using sigaction (SIGPIPE, ...) in syslog implementation

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1453.html">CVE-2004-1453</cve>
                <bugzilla href="http://bugzilla.redhat.com/135125" id="135125">telnet: 0: Name or service not known</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138439" id="138439">re_compile_pattern segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140378" id="140378">[RHEL3] glibc behavior with long lines in /etc/hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142617" id="142617">[RHEL3] libc's getXXent and getXXbyYY are inefficient for large groups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143279" id="143279">x86_64 ecvt() returns "inf" for valid denormalized doubles</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146210" id="146210">zdump -v GMT segfaults in x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146402" id="146402">CAN-2004-1453 Information leak with LD_DEBUG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146710" id="146710">pthread_getspecific gets non-NULL value for new key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147478" id="147478">nscd fails with big group in ldap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149205" id="149205">malloc: top chunk is corrupt w/ MALLOC_CHECK_=3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256012" comment="glibc-common is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256006" comment="glibc-headers is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256008" comment="nptl-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334019" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256004" comment="glibc-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256016" comment="glibc-debug is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256010" comment="glibc-profile is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256002" comment="glibc is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256014" comment="nscd is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256018" comment="glibc-utils is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050267" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:267: Evolution security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-267.html" />
          <reference source="CVE" ref_id="CVE-2005-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2549.html" />
          <reference source="CVE" ref_id="CVE-2005-2550" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2550.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in Evolution.  If a user tries to save a
carefully crafted meeting or appointment, arbitrary code may be executed as
the user running Evolution. The Common Vulnerabilities and Exposures
project has assigned the name CAN-2005-2550 to this issue.

Additionally, several other format string bugs were found in Evolution. If
a user views a malicious vCard, connects to a malicious LDAP server, or
displays a task list from a malicious remote server, arbitrary code may be
executed as the user running Evolution. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2005-2549 to this issue. Please
note that this issue only affects Red Hat Enterprise Linux 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-29" />
        <updated date="2005-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2549.html">CVE-2005-2549</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2550.html">CVE-2005-2550</cve>
                <bugzilla href="http://bugzilla.redhat.com/165235" id="165235">CAN-2005-2549 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL4) (CAN-2005-2550)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165236" id="165236">CAN-2005-2550 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL3)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267002" comment="evolution is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267004" comment="evolution-devel is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267007" comment="evolution is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267008" comment="evolution-devel is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050271" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:271: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:271-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-271.html" />
          <reference source="CVE" ref_id="CVE-2005-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0455.html" />
          <reference source="CVE" ref_id="CVE-2005-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0611.html" />
    
    <description>HelixPlayer is a media player.

A stack based buffer overflow bug was found in HelixPlayer's Synchronized
Multimedia Integration Language (SMIL) file processor. An attacker could
create a specially crafted SMIL file which would execute arbitrary code
when opened by a user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0455 to this issue.

A buffer overflow bug was found in the way HelixPlayer decodes WAV files.
An attacker could create a specially crafted WAV file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0611 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer 1.0.3 which is not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0455.html">CVE-2005-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0611.html">CVE-2005-0611</cve>
                <bugzilla href="http://bugzilla.redhat.com/150098" id="150098">CAN-2005-0455 buffer overflow in helixplayer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150103" id="150103">CAN-2005-0611 .wav overflow in helixplayer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271002" comment="HelixPlayer is earlier than 1:1.0.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050277" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:277: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:277-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-277.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the Mozilla string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Please note that other security issues have been found that affect Mozilla.
These other issues have a lower severity, and are therefore planned to be
released as additional security updates in the future.

Users of Mozilla should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/150124" id="150124">CAN-2005-0255 Memory overwrite in string library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277010" comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277012" comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277004" comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277020" comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277002" comment="mozilla is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277016" comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277014" comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277008" comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277006" comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277018" comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050293" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:293: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:293-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-293.html" />
          <reference source="CVE" ref_id="CVE-2004-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0075.html" />
          <reference source="CVE" ref_id="CVE-2004-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0177.html" />
          <reference source="CVE" ref_id="CVE-2004-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0814.html" />
          <reference source="CVE" ref_id="CVE-2004-1058" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1058.html" />
          <reference source="CVE" ref_id="CVE-2004-1073" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1073.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0137" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0137.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0403.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
    
    <description>The following security issues were fixed:

The Vicam USB driver did not use the copy_from_user function to access
userspace, crossing security boundaries. (CAN-2004-0075)

The ext3 and jfs code did not properly initialize journal descriptor
blocks.  A privileged local user could read portions of kernel memory.
(CAN-2004-0177)

The terminal layer did not properly lock line discipline changes or pending
IO.  An unprivileged local user could read portions of kernel memory, or
cause a denial of service (system crash). (CAN-2004-0814)

A race condition was discovered.  Local users could use this flaw to read
the environment variables of another process that is still spawning via
/proc/.../cmdline. (CAN-2004-1058)

A flaw in the execve() syscall handling was discovered, allowing a local
user to read setuid ELF binaries that should otherwise be protected by
standard permissions. (CAN-2004-1073).  Red Hat originally reported this
as being fixed by RHSA-2004:549, but the associated fix was missing from
that update.

Keith Owens reported a flaw in the Itanium unw_unwind_to_user() function.
A local user could use this flaw to cause a denial of service (system
crash) on the Itanium architecture. (CAN-2005-0135)

A missing Itanium syscall table entry could allow an unprivileged
local user to cause a denial of service (system crash) on the Itanium
architecture. (CAN-2005-0137)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architectures was discovered.  A local user could use this flaw to
access privileged IO ports. (CAN-2005-0204)

A flaw was discovered in the Linux PPP driver.  On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 was
discovered that left a pointer to a freed tty structure.  A local user
could potentially use this flaw to cause a denial of service (system crash)
or possibly gain read or write access to ttys that should normally be
prevented. (CAN-2005-0403)

A flaw in fragment queuing was discovered affecting the netfilter
subsystem.  On systems configured to filter or process network packets (for
example those configured to do firewalling), a remote attacker could send a
carefully crafted set of fragmented packets to a machine and cause a denial
of service (system crash).  In order to sucessfully exploit this flaw, the
attacker would need to know (or guess) some aspects of the firewall ruleset
in place on the target system to be able to craft the right fragmented
packets. (CAN-2005-0449)

Missing validation of an epoll_wait() system call parameter could allow
a local user to cause a denial of service (system crash) on the IBM S/390
and zSeries architectures. (CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered.  A local
user could potentially use this flaw to cause a denial of service (system
crash). (CAN-2005-0749)

A flaw was discovered in the bluetooth driver system.  On system where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

In addition to the security issues listed above, there was an important
fix made to the handling of the msync() system call for a particular case
in which the call could return without queuing modified mmap()'ed data for
file system update. (BZ 147969)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

Red Hat Enterprise Linux 3 users are advised to upgrade their kernels to
the packages associated with their machine architectures/configurations

Please note that the fix for CAN-2005-0449 required changing the
external symbol linkages (kernel module ABI) for the ip_defrag()
and ip_ct_gather_frags() functions.  Any third-party module using either
of these would also need to be fixed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-22" />
        <updated date="2005-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0075.html">CVE-2004-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0177.html">CVE-2004-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0814.html">CVE-2004-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1058.html">CVE-2004-1058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1073.html">CVE-2004-1073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0137.html">CVE-2005-0137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0403.html">CVE-2005-0403</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
                <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293004" comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293002" comment="kernel is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293006" comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293016" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293018" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293014" comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050294" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:294: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 5 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:294-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-294.html" />
          <reference source="CVE" ref_id="CVE-2005-0757" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0757.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the fifth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - support for 2-TB partitions on block devices
  - support for new disk, network, and USB devices
  - support for clustered APIC mode on AMD64 NUMA systems
  - netdump support on AMD64, Intel EM64T, Itanium, and ppc64 systems
  - diskdump support on sym53c8xx and SATA piix/promise adapters
  - NMI switch support on AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 3.

Some key areas affected by these fixes include the kernel's networking,
SATA, TTY, and USB subsystems, as well as the architecture-dependent
handling under the ia64, ppc64, and x86_64 directories.  Scalability
improvements were made primarily in the memory management and file
system areas.

A flaw in offset handling in the xattr file system code backported to
Red Hat Enterprise Linux 3 was fixed.  On 64-bit systems, a user who
can access an ext3 extended-attribute-enabled file system could cause
a denial of service (system crash).  This issue is rated as having a
moderate security impact (CAN-2005-0757).

The following device drivers have been upgraded to new versions:

  3c59x ------ LK1.1.18
  3w-9xxx ---- 2.24.00.011fw (new in Update 5)
  3w-xxxx ---- 1.02.00.037
  8139too ---- (upstream 2.4.29)
  b44 -------- 0.95
  cciss ------ v2.4.54.RH1
  e100 ------- 3.3.6-k2
  e1000 ------ 5.6.10.1-k2
  lpfcdfc ---- 1.0.13 (new in Update 5)
  tg3 -------- 3.22RH

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0757.html">CVE-2005-0757</cve>
                <bugzilla href="http://bugzilla.redhat.com/116289" id="116289">BLKPG_ADD_PARTITION op of BLKPG ioctl doesn't let you add partitions >= 1TB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119351" id="119351">Getting OOM errors on an unconstrained system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121716" id="121716">Raw device I/O transfer size limited to 32KB.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123415" id="123415">API Breakage: NFS "No locks available" with kernel 2.4.21-15.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124600" id="124600">Unexpected error: VFS: Busy inodes after unmount. Self-destruct in 5 seconds.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127066" id="127066">Panic is occurring in the I/O completion interrupt handling for the character interface driver (sg).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128176" id="128176">Add the 3w-9xxx module (required for the 9000 series 3ware cards)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129084" id="129084">ICH6 SATA support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130113" id="130113">Strange output of /proc/mtrr</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130365" id="130365">Request to include EMC Celerra and iSCSI devices to the black list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131981" id="131981">O_DIRECT doesn't work on LVM devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132162" id="132162">NFS intr flag prevents core dumps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132257" id="132257">LTC-8859: softdog.o need to be included into RHEL distributions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132339" id="132339">x86 compatibility mode apps using signals crash under EM64T</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132494" id="132494">POSIX Asynchronous IO support is unstable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132838" id="132838">Kernel Panic: Unable to satisfy kernel paging request... when starting ServerVantage.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133020" id="133020">[RHEL3][IA32E][X86_64]Wrong FPU IP and DP in the SIGFPE signal context</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133388" id="133388">3c59x: eth0: Transmit error, Tx status register d0. (10Mb hub)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133905" id="133905">kernel crash, fatal exception, accessing /proc, EXT3-fs error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134832" id="134832">Ia32e + Intel SATA 82801EB + kernel 2.4.21-20EL;   unable to mount root partition.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135266" id="135266">Panics while backing up LVM snapshots</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135583" id="135583">RHEL3U3 panics on boot for HP rx5670</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135688" id="135688">NFS ESTALES returned on open [IT50092]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136317" id="136317">When copying rootfs to /mnt/sdc/, rsync accessed /proc/kcore and kernel crashed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136398" id="136398">NFS direct reads don't flush dirty cached pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137201" id="137201">RHEL3U2/U3 x86-64 - /proc/mtrr reported incorrectly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137519" id="137519">ps shows bad PPID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137830" id="137830">worktodo does not support NFS aio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137961" id="137961">tg3 fiber auto-negotiation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138182" id="138182">Kernel hang when cat'ting file on intr NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138240" id="138240">MCA in tulip on ifconfig down/reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138815" id="138815">[RHEL3-U5][Diskdump] Stalls before printing "CPU frozen"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138827" id="138827">usb: raced timeout errors when using usb/serial adapter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138905" id="138905">Unkillable processes under 64bit Linux which use Kernel Asynchronous I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139421" id="139421">[RHEL3-U4][Diskdump] Diskdump failed with serial console enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139434" id="139434">[RHEL3-U4][Diskdump] Segmentation Fault after cliloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139440" id="139440">[RHEL3-U5][Diskdump] All CPUs are displayed in CPU frozen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139465" id="139465">em64t/ia32e kernel panic: 'interrupt handler - not syncing' during heavy network I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140083" id="140083">lx-choptp19 crashed running 2.4.21-20.EL.BZ131027.hotfixhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140331" id="140331">stack overflows can occur on x86_64 under stack pressure when softirq's are handled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140552" id="140552">Kernel wrongly complains about application bug when loading modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140585" id="140585">[RHEL3][PATCH] SIOCGHWADDR does not clear buffer for ppp connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140616" id="140616">RHEL3 PATCH dev.c: clear SIOCGIFHWADDR buffer if !dev->addr_len</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140790" id="140790">e100 and e1000 drivers should return EINVAL when ethtool tries to set rx-mini or rx-jumbo</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141282" id="141282">nptl futex_wait fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141377" id="141377">[PATCH] memory leak in ipv6   ip6_{push,flush}_pending_frames()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141388" id="141388">FAT32 file system zero length files corruption after remount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141697" id="141697">ATAPI-CDROM not accessible with kernel options ide-scsi and swiotlb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141757" id="141757">Infinite loop when syncing over automounted NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142683" id="142683">bonding with mii monitoring does not work with realtek card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142725" id="142725">[PATCH] video1394 fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142954" id="142954">sata_sx4 4GB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143542" id="143542">Unable to handle kernel NULL pointer dereference at virtual address 00000004</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143565" id="143565">NIC BCM4401 on Dell Inspiron 5100 broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143625" id="143625">kernel can not register scsi LUNs above 7 for mylexFFx2 FC RAID controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144260" id="144260">U4 kernel sound broken on certain AC 97 systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144360" id="144360">Fibre Channel tape speed regression (qla2200)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144990" id="144990">Anaconda installer partion error large RAID volume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145331" id="145331">kernel panic in get_signal_to_deliver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145409" id="145409">panic_on_oops hook removed on ia64 by diskdump patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145563" id="145563">tar crashes DELL server every 4th day.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145746" id="145746">mmap() system call can return Nil</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146345" id="146345">recv returns EAGAIN instead of EINTR when interrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146501" id="146501">ext2/ext3 w/ 1024 blocksize eats all memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147541" id="147541">rsync creating truncated files on fat32 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147580" id="147580">Race condition in md subsystem causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147704" id="147704">laus incorrectly truncates path string when predicate filter is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151934" id="151934">Running lshw causes MCA on Olympia rx8620</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152627" id="152627">sata_sil missing PCI IDs for ATI SATA controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152959" id="152959">Repeated Kernel Panics while using LVM Snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156617" id="156617">SIGCHLD set to SIG_IGN but calls wait().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156882" id="156882">aggressively clean bhs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156928" id="156928">sata_promise in 2.4.21-27.0.4.EL doesn't support Promise sataII 150 tx4 yet</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294006" comment="kernel-source is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294002" comment="kernel is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294008" comment="kernel-doc is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294018" comment="kernel-hugemem is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294014" comment="kernel-BOOT is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294004" comment="kernel-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294012" comment="kernel-smp is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050300" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:300: libexif security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:300-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-300.html" />
          <reference source="CVE" ref_id="CVE-2005-0664" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0664.html" />
    
    <description>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

A bug was found in the way libexif parses EXIF tags. An attacker could
create a carefully crafted EXIF image file which could cause image viewers
linked against libexif to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0664 to this issue.

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0664.html">CVE-2005-0664</cve>
                <bugzilla href="http://bugzilla.redhat.com/150503" id="150503">CAN-2005-0664 buffer overflow in libexif</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300004" comment="libexif-devel is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300005" comment="libexif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300002" comment="libexif is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300003" comment="libexif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050306" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:306: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:306-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-306.html" />
          <reference source="CVE" ref_id="CVE-2005-0699" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0699.html" />
          <reference source="CVE" ref_id="CVE-2005-0704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0704.html" />
          <reference source="CVE" ref_id="CVE-2005-0705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0705.html" />
          <reference source="CVE" ref_id="CVE-2005-0739" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0739.html" />
          <reference source="CVE" ref_id="CVE-2005-0765" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0765.html" />
          <reference source="CVE" ref_id="CVE-2005-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0766.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.


A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.

A buffer overflow flaw was discovered in the Etheric dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0704 to this issue.

The GPRS-LLC dissector could crash if the "ignore cipher bit" option was
set. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0705 to this issue.

A buffer overflow flaw was discovered in the 3GPP2 A11 dissector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0699 to this issue.

A buffer overflow flaw was discovered in the IAPP dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0739 to this issue.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-18" />
        <updated date="2005-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0699.html">CVE-2005-0699</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0704.html">CVE-2005-0704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0705.html">CVE-2005-0705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0739.html">CVE-2005-0739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0765.html">CVE-2005-0765</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0766.html">CVE-2005-0766</cve>
                <bugzilla href="http://bugzilla.redhat.com/150705" id="150705">CAN-2005-0699 Multiple ethereal issues (CAN-2005-0704 CAN-2005-0705)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306004" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306002" comment="ethereal is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306008" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306007" comment="ethereal is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050307" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:307: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-307.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

Users of KDE should upgrade to these erratum packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-06" />
        <updated date="2005-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/151373" id="151373">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307002" comment="kdelibs is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307004" comment="kdelibs-devel is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050320" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:320: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:320-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-320.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

Additionally, a bug was fixed which caused ImageMagick(TM) to occasionally
segfault when writing TIFF images to standard output.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/142045" id="142045">Segmentation fault on conversion to TIFF (possible libtiff bug)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320010" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320004" comment="ImageMagick-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320006" comment="ImageMagick-perl is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320002" comment="ImageMagick is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320008" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040480009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050323" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:323: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:323-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-323.html" />
          <reference source="CVE" ref_id="CVE-2004-0906" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0906.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2004-1613" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1613.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0147.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1380 to this issue.

A bug was found in the way Mozilla allowed plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0232 to this issue.

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0149 to
this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0147 to this issue.

A bug was found in the way Mozilla handles certain start tags followed by a
NULL character.  A malicious web page could cause Mozilla to crash when
viewed by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1613 to this issue.

A bug was found in the way Mozilla sets file permissions when installing
XPI packages.  It is possible for an XPI package to install some files
world readable or writable, allowing a malicious local user to steal
information or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0906 to
this issue.

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0141 to this issue.

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0144 to this issue.

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.4.4 and additional backported patches to correct
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0906.html">CVE-2004-0906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1613.html">CVE-2004-1613</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0147.html">CVE-2005-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
                <bugzilla href="http://bugzilla.redhat.com/145597" id="145597">CAN-2005-0141 Link opened in new tab can load a local file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145609" id="145609">CAN-2005-0144 Secure site lock can be spoofed with view-source:</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145610" id="145610">CAN-2004-1380 Input stealing from other tabs (CAN-2004-1381)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145614" id="145614">CAN-2005-0147 Browser responds to proxy auth request from non-proxy server (ssl/https)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145615" id="145615">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151209" id="151209">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151492" id="151492">CAN-2004-1613 Mozilla start tag NULL character DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151494" id="151494">CAN-2004-0906 Mozilla XPI installer insecure file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151496" id="151496">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323018" comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323014" comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323016" comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323010" comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323002" comment="mozilla is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323020" comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323006" comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323004" comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323012" comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323008" comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050325" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:325: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-325.html" />
          <reference source="CVE" ref_id="CVE-2005-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0237.html" />
          <reference source="CVE" ref_id="CVE-2005-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0365.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

The International Domain Name (IDN) support in the Konqueror browser
allowed remote attackers to spoof domain names using punycode encoded
domain names.  Such domain names are decoded in URLs and SSL certificates
in a way that uses homograph characters from other character sets, which
facilitates phishing attacks. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0237 to this issue.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

A flaw in the dcopidlng script was discovered. The dcopidlng script would
create temporary files with predictable filenames which could allow local
users to overwrite arbitrary files via a symlink attack. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0365 to this issue.

Users of KDE should upgrade to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0237.html">CVE-2005-0237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0365.html">CVE-2005-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/147405" id="147405">CAN-2005-0237 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148822" id="148822">CAN-2005-0365 dcopidlng insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150090" id="150090">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325002" comment="kdelibs is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325004" comment="kdelibs-devel is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050327" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:327: telnet security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-327.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>The telnet package provides a command line telnet client. The telnet-server
package includes a telnet daemon, telnetd, that supports remote login to
the host machine.

Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468
and CAN-2005-0469 to these issues.

Additionally, the following bugs have been fixed in these erratum packages
for Red Hat Enterprise Linux 2.1 and Red Hat Enterprise Linux 3:

- telnetd could loop on an error in the child side process

- There was a race condition in telnetd on a wtmp lock on some occasions

- The command line in the process table was sometimes too long and caused
bad output from the ps command

- The 8-bit binary option was not working

Users of telnet should upgrade to this updated package, which contains
backported patches to correct these issues.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/126858" id="126858">Too long /proc/X/cmdline: bad ps output when piped to less/more</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145004" id="145004">telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145636" id="145636">[PATCH] telnetd loops on child IO error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147003" id="147003">[RHEL3] telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151297" id="151297">CAN-2005-0469 slc_add_reply() Buffer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151301" id="151301">CAN-2005-0468 env_opt_add() Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327002" comment="telnet is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327004" comment="telnet-server is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327007" comment="telnet is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327008" comment="telnet-server is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050330" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:330: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:330-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-330.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

The krb5-workstation package includes a Kerberos-aware telnet client. 
Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468 and
CAN-2005-0469 to these issues.

Users of krb5 should update to these erratum packages which contain a
backported patch to correct this issue.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/151267" id="151267">CAN-2005-0469  Multiple Telnet Client issues (CAN-2005-0468)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330006" comment="krb5-libs is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330004" comment="krb5-devel is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330008" comment="krb5-server is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330002" comment="krb5 is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330010" comment="krb5-workstation is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330015" comment="krb5-libs is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330014" comment="krb5-devel is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330016" comment="krb5-server is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330013" comment="krb5 is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330017" comment="krb5-workstation is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040236011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050331" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:331: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:331-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-331.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
malicious XPM file that would execute arbitrary code if opened by a victim
using an application linked to the vulnerable library. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0605 to this issue.

The updated XFree86 packages also address the following minor issues:

- Updated XFree86-4.3.0-keyboard-disable-ioport-access-v3.patch to make
  warning messages less alarmist.

- Backported XFree86-4.3.0-libX11-stack-overflow.patch from xorg-x11-6.8.1
  packaging to fix stack overflow in libX11, which was discovered by new
  security features of gcc4.

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/132885" id="132885">libX11 overflows it's own stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150038" id="150038">CAN-2005-0605 XPM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061023" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331012" comment="XFree86-xdm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061053" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331016" comment="XFree86-libs-data is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061037" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331046" comment="XFree86-doc is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061011" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061027" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331002" comment="XFree86 is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061039" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331014" comment="XFree86-libs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061035" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331060" comment="XFree86-sdk is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040478061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331008" comment="XFree86-xfs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061055" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331048" comment="XFree86-Xnest is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061057" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061021" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061043" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061025" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061031" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331058" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061041" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061019" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331018" comment="XFree86-base-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061009" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331006" comment="XFree86-font-utils is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061017" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331052" comment="XFree86-tools is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061045" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331050" comment="XFree86-Xvfb is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061059" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331010" comment="XFree86-twm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061049" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331054" comment="XFree86-xauth is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061051" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331004" comment="XFree86-devel is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040061013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050332" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:332: xloadimage security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-332.html" />
          <reference source="CVE" ref_id="CVE-2005-0638" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0638.html" />
    
    <description>The xloadimage utility displays images in an X Window System window,
loads images into the root window, or writes images into a file.
Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM,
and XBM).

A flaw was discovered in xloadimage where filenames were not properly
quoted when calling the gunzip command.  An attacker could create a file
with a carefully crafted filename so that it would execute arbitrary
commands if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0638 to
this issue.

Another bug in xloadimage would cause it to crash if called with certain
invalid TIFF, PNM, PBM, or PPM file names.

All users of xloadimage should upgrade to this erratum package which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-04-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0638.html">CVE-2005-0638</cve>
                <bugzilla href="http://bugzilla.redhat.com/70867" id="70867">xloadimage crashes with some TIFF images</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/78481" id="78481">bad source code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150700" id="150700">CAN-2005-0638 xloadimage multiple issues.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332002" comment="xloadimage is earlier than 0:4.1-34.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332005" comment="xloadimage is earlier than 0:4.1-34.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050334" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:334: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:334-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-334.html" />
          <reference source="CVE" ref_id="CVE-2005-0709" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0709.html" />
          <reference source="CVE" ref_id="CVE-2005-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0710.html" />
          <reference source="CVE" ref_id="CVE-2005-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0711.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes several security risks in the MySQL server.

Stefano Di Paola discovered two bugs in the way MySQL handles user-defined
functions. A user with the ability to create and execute a user defined
function could potentially execute arbitrary code on the MySQL server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2005-0709 and CAN-2005-0710 to these issues.

Stefano Di Paola also discovered a bug in the way MySQL creates temporary
tables. A local user could create a specially crafted symlink which could
result in the MySQL server overwriting a file which it has write access to.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-0711 to this issue.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0709.html">CVE-2005-0709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0710.html">CVE-2005-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0711.html">CVE-2005-0711</cve>
                <bugzilla href="http://bugzilla.redhat.com/150868" id="150868">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150871" id="150871">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151051" id="151051">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152344" id="152344">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334002" comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334004" comment="mysql-server is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334008" comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334006" comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334011" comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334012" comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334014" comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334013" comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040569007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050335" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:335: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:335-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-335.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. (CAN-2005-0147)

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. (CAN-2004-1380)

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. (CAN-2005-0149)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Mozilla saves temporary files. Temporary files
are saved with world readable permissions, which could allow a local
malicious user to view potentially sensitive data. (CAN-2005-0142)

A bug was found in the way Mozilla handles synthetic middle click events. 
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

A bug was found in the way Mozilla processes XUL content.  If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. (CAN-2005-0141)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. (CAN-2005-0144)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can display the secure site icon by loading a binary
file from a secured site. (CAN-2005-0143)

A bug was found in the way Mozilla displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.6 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
                <bugzilla href="http://bugzilla.redhat.com/142508" id="142508">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144228" id="144228">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146188" id="146188">CAN-2005-0141 multiple mozilla issues CAN-2004-1316 CAN-2005-0142 CAN-2005-0143 CAN-2005-0144 CAN-2004-1380 CAN-2004-1381 CAN-2005-0146 CAN-2005-0147 CAN-2005-0149</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150866" id="150866">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151730" id="151730">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335018" comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335014" comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335016" comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335010" comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335002" comment="mozilla is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335020" comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335006" comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335004" comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335012" comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335008" comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335022" comment="devhelp is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335026" comment="evolution is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335028" comment="evolution-devel is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050336" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:336: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-336.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0402.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A buffer overflow bug was found in the way Firefox processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Firefox processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0401 to this issue.

A bug was found in the way Firefox bookmarks content to the sidebar. If a
user can be tricked into bookmarking a malicious web page into the sidebar
panel, that page could execute arbitrary programs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0402 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0402.html">CVE-2005-0402</cve>
                <bugzilla href="http://bugzilla.redhat.com/150877" id="150877">CAN-2005-0399 firefox GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151153" id="151153">CAN-2005-0402 arbitrary code execution via sidebar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151714" id="151714">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050336002" comment="firefox is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050337" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:337: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-337.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A buffer overflow bug was found in the way Thunderbird processes GIF
images. It is possible for an attacker to create a specially crafted GIF
image, which when viewed by a victim will execute arbitrary code as the
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0399 to this issue.

A bug was found in the Thunderbird string handling functions. If a
malicious website is able to exhaust a system's memory, it becomes possible
to execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Users of Thunderbird are advised to upgrade to this updated package which
contains Thunderbird version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/149883" id="149883">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150874" id="150874">CAN-2005-0399 thunderbird GIF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050337002" comment="thunderbird is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050340" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:340: curl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:340-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-340.html" />
          <reference source="CVE" ref_id="CVE-2005-0490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0490.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and
Dict servers, using any of the supported protocols. cURL is designed
to work without user interaction or any kind of interactivity. 

Multiple buffer overflow bugs were found in the way curl processes base64
encoded replies. If a victim can be tricked into visiting a URL with curl,
a malicious web server could execute arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0490 to this issue.

All users of curl are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0490.html">CVE-2005-0490</cve>
                <bugzilla href="http://bugzilla.redhat.com/149322" id="149322">CAN-2005-0490 Multiple stack based buffer overflows in curl</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340002" comment="curl is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340004" comment="curl-devel is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340007" comment="curl is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340008" comment="curl-devel is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050343" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:343: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-343.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gdk-pixbuf. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gdk-pixbuf are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152315" id="152315">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343002" comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343009" comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040103003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050344" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:344: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-344.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

A bug was found in the way gtk2 processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gtk2. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gtk2 are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152317" id="152317">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344002" comment="gtk2 is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344004" comment="gtk2-devel is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344007" comment="gtk2 is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344008" comment="gtk2-devel is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040466005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050345" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:345: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:345-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-345.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- Files with a size of 2 GB and larger were not entered into the slocate
  database.

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems).

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/132571" id="132571">Files > 2 GB are not entered into slocate data base</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169453" id="169453">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050345002" comment="slocate is earlier than 0:2.7-3.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050346" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:346: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-346.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems.)

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

- The default configuration excluded /mnt/floppy, but not /media.

- The default configuration did not exclude nfs4 file systems.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152253" id="152253">Incorrect path in /etc/updatedb.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156091" id="156091">updatedb indexes nfs4 filesystems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165430" id="165430">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050346002" comment="slocate is earlier than 0:2.7-13.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040041003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050354" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:354: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-354.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>TeTeX is an implementation of TeX for Linux or UNIX systems. TeX takes
a text file and a set of formatting commands as input and creates a
typesetter-independent .dvi (DeVice Independent) file as output.

A number of security flaws have been found affecting libraries used
internally within teTeX.  An attacker who has the ability to trick a user
into processing a malicious file with teTeX could cause teTeX to crash or
possibly execute arbitrary code. 

A number of integer overflow bugs that affect Xpdf were discovered. The
teTeX package contains a copy of the Xpdf code used for parsing PDF files
and is therefore affected by these bugs. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0888 and
CAN-2004-1125 to these issues.

A number of integer overflow bugs that affect libtiff were discovered.  The
teTeX package contains an internal copy of libtiff used for parsing TIFF
image files and is therefore affected by these bugs.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0803, CAN-2004-0804 and CAN-2004-0886 to these issues.

Also latex2html is added to package tetex-latex for 64bit platforms.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/137475" id="137475">CAN-2004-0888 xpdf integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137607" id="137607">CAN-2004-0803 multiple issues in libtiff (CAN-2004-0804 CAN-2004-0886)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137973" id="137973">tetex-latex package missing latex2html</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145129" id="145129">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354006" comment="tetex-xdvi is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354002" comment="tetex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354012" comment="tetex-fonts is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354014" comment="tetex-doc is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354004" comment="tetex-latex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354008" comment="tetex-dvips is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354010" comment="tetex-afm is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050357" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:357: gzip security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-357.html" />
          <reference source="CVE" ref_id="CVE-2005-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0758.html" />
          <reference source="CVE" ref_id="CVE-2005-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0988.html" />
          <reference source="CVE" ref_id="CVE-2005-1228" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1228.html" />
    
    <description>The gzip package contains the GNU gzip data compression program.

A bug was found in the way zgrep processes file names. If a user can be
tricked into running zgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running zgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0758 to this issue.

A bug was found in the way gunzip modifies permissions of files being
decompressed. A local attacker with write permissions in the directory in
which a victim is decompressing a file could remove the file being written
and replace it with a hard link to a different file owned by the victim. 
gunzip then gives the linked file the permissions of the uncompressed file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0988 to this issue.

A directory traversal bug was found in the way gunzip processes the -N
flag. If a victim decompresses a file with the -N flag, gunzip fails to
sanitize the path which could result in a file owned by the victim being
overwritten. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1228 to this issue.

Users of gzip should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0758.html">CVE-2005-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0988.html">CVE-2005-0988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1228.html">CVE-2005-1228</cve>
                <bugzilla href="http://bugzilla.redhat.com/121514" id="121514">CAN-2005-0758 zgrep has security issue in sed usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155745" id="155745">CAN-2005-0988 Race condition in gzip</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156266" id="156266">CAN-2005-1228 directory traversal bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357002" comment="gzip is earlier than 0:1.3.3-12.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357005" comment="gzip is earlier than 0:1.3.3-15.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050358" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:358: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:358-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-358.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet.

An integer overflow flaw was found in PCRE, a Perl-compatible regular
expression library included within Exim.  A local user could create a
maliciously crafted regular expression in such as way that they could gain
the privileges of the 'exim' user.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2491 to this issue.  These
erratum packages change Exim to use the system PCRE library instead of the
internal one.  

These packages also fix a minor flaw where the Exim Monitor was incorrectly
computing free space on very large file systems.

Users should upgrade to these erratum packages and also ensure they have
updated the system PCRE library, for which erratum packages are available
seperately in RHSA-2005:761</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166332" id="166332">CAN-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358002" comment="exim is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050361" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:361: vixie-cron security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-361.html" />
          <reference source="CVE" ref_id="CVE-2005-1038" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1038.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is
possible for a local attacker to execute the crontab command in such a way
that they can view the contents of another user's crontab file. The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1038 to
this issue. 

Additionally, this update addresses the following issues:

o Fixed improper limits on filename and command line lengths 
o Improved PAM access control conforming to EAL certification requirements
o Improved reliability when running in a chroot environment
o Mail recipient name checking disabled by default, can be re-enabled 
o Added '-p' "permit all crontabs" option to disable crontab mode checking

All users of vixie-cron should upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1038.html">CVE-2005-1038</cve>
                <bugzilla href="http://bugzilla.redhat.com/147636" id="147636">cron fails to run user jobs and gives vague error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154920" id="154920">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159216" id="159216">vixie-cron updates for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163881" id="163881">Cron no longer allows read-only crontabs, enforces write access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163882" id="163882">cron fails with pam_access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163885" id="163885">crontab truncates file names greater than 100 characters.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163888" id="163888">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163889" id="163889">[PATCH] List corruption when items are removed from /etc/cron.d</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361002" comment="vixie-cron is earlier than 4:4.1-36.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050365" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:365: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:365-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-365.html" />
          <reference source="CVE" ref_id="CVE-2005-0965" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0965.html" />
          <reference source="CVE" ref_id="CVE-2005-0966" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0966.html" />
          <reference source="CVE" ref_id="CVE-2005-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0967.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

A buffer overflow bug was found in the way gaim escapes HTML. It is
possible that a remote attacker could send a specially crafted message to a
Gaim client, causing it to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0965 to this issue.

A bug was found in several of gaim's IRC processing functions. These
functions fail to properly remove various markup tags within an IRC
message. It is possible that a remote attacker could send a specially
crafted message to a Gaim client connected to an IRC server, causing it to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0966 to this issue.

A bug was found in gaim's Jabber message parser. It is possible for a
remote Jabber user to send a specially crafted message to a Gaim client,
causing it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0967 to this issue.

In addition to these denial of service issues, multiple minor upstream
bugfixes are included in this update.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.2.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-12" />
        <updated date="2005-04-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0965.html">CVE-2005-0965</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0966.html">CVE-2005-0966</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0967.html">CVE-2005-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/153311" id="153311">CAN-2005-0965 Gaim remote DoS issues (CAN-2005-0966)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153761" id="153761">CAN-2005-0967 jabber DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365002" comment="gaim is earlier than 1:1.2.1-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365005" comment="gaim is earlier than 1:1.2.1-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040033003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050366" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:366: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:366-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-366.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0207" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0207.html" />
          <reference source="CVE" ref_id="CVE-2005-0210" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0210.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0400" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0400.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0529" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0529.html" />
          <reference source="CVE" ref_id="CVE-2005-0530" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0530.html" />
          <reference source="CVE" ref_id="CVE-2005-0531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0531.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
          <reference source="CVE" ref_id="CVE-2005-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0767.html" />
          <reference source="CVE" ref_id="CVE-2005-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0815.html" />
          <reference source="CVE" ref_id="CVE-2005-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0839.html" />
          <reference source="CVE" ref_id="CVE-2005-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0867.html" />
          <reference source="CVE" ref_id="CVE-2005-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0977.html" />
          <reference source="CVE" ref_id="CVE-2005-1041" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1041.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw in the fib_seq_start function was discovered. A local user could use
this flaw to cause a denial of service (system crash) via /proc/net/route.
(CAN-2005-1041)

A flaw in the tmpfs file system was discovered. A local user could use this
flaw to cause a denial of service (system crash). (CAN-2005-0977)

An integer overflow flaw was found when writing to a sysfs file. A local
user could use this flaw to overwrite kernel memory, causing a denial of
service (system crash) or arbitrary code execution. (CAN-2005-0867)

Keith Owens reported a flaw in the Itanium unw_unwind_to_user function. A
local user could use this flaw to cause a denial of service (system crash)
on Itanium architectures. (CAN-2005-0135)

A flaw in the NFS client O_DIRECT error case handling was discovered. A
local user could use this flaw to cause a denial of service (system crash).
(CAN-2005-0207)

A small memory leak when defragmenting local packets was discovered that
affected the Linux 2.6 kernel netfilter subsystem.  A local user could send
a large number of carefully crafted fragments leading to memory exhaustion
(CAN-2005-0210)

A flaw was discovered in the Linux PPP driver. On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw was discovered in the ext2 file system code. When a new directory is
created, the ext2 block written to disk is not initialized, which could
lead to an information leak if a disk image is made available to
unprivileged users. (CAN-2005-0400)

A flaw in fragment queuing was discovered that affected the Linux kernel
netfilter subsystem. On systems configured to filter or process network
packets (e.g. firewalling), a remote attacker could send a carefully
crafted set of fragmented packets to a machine and cause a denial of
service (system crash). In order to sucessfully exploit this flaw, the
attacker would need to know or guess some aspects of the firewall ruleset
on the target system. (CAN-2005-0449)

A number of flaws were found in the Linux 2.6 kernel. A local user could
use these flaws to read kernel memory or cause a denial of service (crash).
(CAN-2005-0529, CAN-2005-0530, CAN-2005-0531)

An integer overflow in sys_epoll_wait in eventpoll.c was discovered. A
local user could use this flaw to overwrite low kernel memory. This memory
is usually unused, not usually resulting in a security consequence.
(CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered. A local
user could potentially use this flaw to cause a denial of service (crash).
(CAN-2005-0749)

A flaw was discovered in the bluetooth driver system. On systems where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

A race condition was discovered that affected the Radeon DRI driver. A
local user who has DRI privileges on a Radeon graphics card may be able to
use this flaw to gain root privileges. (CAN-2005-0767)

Multiple range checking flaws were discovered in the iso9660 file system
handler. An attacker could create a malicious file system image which would
cause a denial or service or potentially execute arbitrary code if mounted.
(CAN-2005-0815)

A flaw was discovered when setting line discipline on a serial tty. A local
user may be able to use this flaw to inject mouse movements or keystrokes
when another user is logged in. (CAN-2005-0839)

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.

Please note that</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0207.html">CVE-2005-0207</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0210.html">CVE-2005-0210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0400.html">CVE-2005-0400</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0529.html">CVE-2005-0529</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0530.html">CVE-2005-0530</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0531.html">CVE-2005-0531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0767.html">CVE-2005-0767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0815.html">CVE-2005-0815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0839.html">CVE-2005-0839</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0867.html">CVE-2005-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0977.html">CVE-2005-0977</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1041.html">CVE-2005-1041</cve>
                <bugzilla href="http://bugzilla.redhat.com/147468" id="147468">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148868" id="148868">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148878" id="148878">CAN-2005-0207 nfs client O_DIRECT oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149466" id="149466">CAN-2005-0529 Sign handling issues on v2.6 (CAN-2005-0530 CAN-2005-0531)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149589" id="149589">CAN-2005-0209 netfilter SKB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151240" id="151240">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151249" id="151249">CAN-2005-0736 epoll overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151902" id="151902">CAN-2005-0767 drm race in radeon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152177" id="152177">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152399" id="152399">CAN-2005-0400 ext2 mkdir() directory entry random kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152405" id="152405">CAN-2005-0815 isofs range checking flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152410" id="152410">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152417" id="152417">CAN-2005-0839 N_MOUSE line discipline flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152561" id="152561">CAN-2005-0977 tmpfs truncate bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154219" id="154219">CAN-2005-0867 sysfs signedness problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154551" id="154551">CAN-2005-1041 crash while reading /proc/net/route</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366002" comment="kernel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366006" comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366004" comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366008" comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050373" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:373: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-373.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management.

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet which will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc which can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally the following bugs have been fixed:
 - snmpwalk no longer hangs when a non-existant pid is listed. 
 - snmpd no longer segfaults due to incorrect handling of lmSensors. 
 - an incorrect assignment leading to invalid values in ASN mibs has been
   fixed.
 - on systems running a 64-bit kernel, the values in /proc/net/dev no 
   longer become too large to fit in a 32-bit object. 
 - the net-snmp-devel packages correctly depend on elfutils-libelf-devel.
 - large file systems are correctly handled
 - snmp daemon now reports gigabit Ethernet speeds correctly
 - fixed consistency between IP adresses and hostnames in configuration file

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/130252" id="130252">net-snmp-devel should depend on elfutils-libelf-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152448" id="152448">snmpd.conf hostname vs. IP inconsistancy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162907" id="162907">CAN-2005-2177 net-snmp denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164639" id="164639">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373004" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373010" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373008" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373006" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373002" comment="net-snmp is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050375" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:375: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:375-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-375.html" />
          <reference source="CVE" ref_id="CVE-2005-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0941.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap based buffer overflow bug was found in the OpenOffice.org DOC file
processor. An attacker could create a carefully crafted DOC file in such a
way that it could cause OpenOffice.org to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0941 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0941.html">CVE-2005-0941</cve>
                <bugzilla href="http://bugzilla.redhat.com/154540" id="154540">CAN-2005-0941 openoffice.org heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375006" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375002" comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375004" comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375011" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375009" comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375012" comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375010" comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050377" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:377: sharutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-377.html" />
          <reference source="CVE" ref_id="CVE-2004-1772" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1772.html" />
          <reference source="CVE" ref_id="CVE-2004-1773" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1773.html" />
          <reference source="CVE" ref_id="CVE-2005-0990" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0990.html" />
    
    <description>The sharutils package contains a set of tools for encoding and decoding
packages of files in binary or text format.

A stack based overflow bug was found in the way shar handles the -o option.
If a user can be tricked into running a specially crafted command, it could
lead to arbitrary code execution.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1772 to this issue.
Please note that this issue does not affect Red Hat Enterprise Linux 4.

Two buffer overflow bugs were found in sharutils. If an attacker can place
a malicious 'wc' command on a victim's machine, or trick a victim into
running a specially crafted command, it could lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1773 to this issue.

A bug was found in the way unshar creates temporary files. A local user
could use symlinks to overwrite arbitrary files the victim running unshar
has write access to. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0990 to this issue.

All users of sharutils should upgrade to this updated package, which
includes backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1772.html">CVE-2004-1772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1773.html">CVE-2004-1773</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0990.html">CVE-2005-0990</cve>
                <bugzilla href="http://bugzilla.redhat.com/152571" id="152571">CAN-2004-1772 buffer overflow with -o option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152573" id="152573">CAN-2004-1773 Buffer overflows in unshar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154049" id="154049">CAN-2005-0990 insecure temp file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377002" comment="sharutils is earlier than 0:4.2.1-16.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377005" comment="sharutils is earlier than 0:4.2.1-22.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050378" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:378: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:378-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-378.html" />
          <reference source="CVE" ref_id="CVE-2005-1111" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1111.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

A race condition bug was found in cpio. It is possible for a local
malicious user to modify the permissions of a local file if they have write
access to a directory in which a cpio archive is being extracted. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1111 to this issue.

Additionally, this update adds cpio support for archives larger than 2GB.
However, the size of individual files within an archive is limited to 4GB.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1111.html">CVE-2005-1111</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154507" id="154507">511278 - needs fix for RHEL 4 on cpio bugzilla 105617</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155749" id="155749">CVE-2005-1111 Race condition in cpio</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378002" comment="cpio is earlier than 0:2.5-4.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378005" comment="cpio is earlier than 0:2.5-8.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050381" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:381: nasm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:381-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-381.html" />
          <reference source="CVE" ref_id="CVE-2004-1287" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1287.html" />
          <reference source="CVE" ref_id="CVE-2005-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1194.html" />
    
    <description>NASM is an 80x86 assembler.

Two stack based buffer overflow bugs have been found in nasm. An attacker
could create an ASM file in such a way that when compiled by a victim,
could execute arbitrary code on their machine. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1287
and CAN-2005-1194 to these issues.

All users of nasm are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1287.html">CVE-2004-1287</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1194.html">CVE-2005-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/143081" id="143081">CAN-2004-1287 Bernstein class reports buffer overflow in nasm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152962" id="152962">CAN-2005-1194 Buffer overflow in the ieee_putascii() function</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381004" comment="nasm-doc is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381002" comment="nasm is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381006" comment="nasm-rdoff is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381010" comment="nasm-doc is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381009" comment="nasm is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381011" comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050383" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:383: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:383-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-383.html" />
          <reference source="CVE" ref_id="CVE-2005-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0752.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1158.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Vladimir V. Perepelitsa discovered a bug in the way Firefox handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Omar Khan discovered a bug in the way Firefox processes the PLUGINSPAGE
tag. It is possible for a malicious web page to trick a user into pressing
the "manual install" button for an unknown plugin leading to arbitrary
javascript code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0752 to this issue.

Doron Rosenberg discovered a bug in the way Firefox displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1153 to this issue.

A bug was found in the way Firefox handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1154 to
this issue.

Michael Krax discovered a bug in the way Firefox handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1155 to this issue.

Michael Krax discovered a bug in the way Firefox installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and steal sensitive information.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2005-1156 and CAN-2005-1157 to these issues. 

Kohei Yoshino discovered a bug in the way Firefox opens links in its
sidebar. A malicious web page could construct a link in such a way that,
when clicked on, could execute arbitrary javascript with elevated
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1158 to this issue.

A bug was found in the way Firefox validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1159 to this issue.

A bug was found in the way the Firefox privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1160 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.3 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-21" />
        <updated date="2005-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0752.html">CVE-2005-0752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1158.html">CVE-2005-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155114" id="155114">CAN-2005-0752 Multiple firefox issues. (CAN-2005-0989)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050383002" comment="firefox is earlier than 0:1.0.3-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050384" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:384: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-384.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found with the way Mozilla displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0143 CAN-2005-0593)

A bug was found in the way Mozilla handles synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

Several bugs were found with the way Mozilla handles temporary files. A
local user could view sensitive temporary information or delete arbitrary
files. (CAN-2005-0142 CAN-2005-0578)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

Several bugs were found in the way Mozilla displays alert dialogs. It is
possible for a malicious webserver or website to trick a user into thinking
the dialog window is being generated from a trusted site. (CAN-2005-0586
CAN-2005-0591 CAN-2005-0585 CAN-2005-0590 CAN-2005-0584)

A bug was found in the Mozilla javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed,
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Mozilla allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527)

A bug was found in the way Mozilla handles anonymous functions during
regular expression string replacement. It is possible for a malicious web
page to capture a random block of browser memory. (CAN-2005-0989)

A bug was found in the way Mozilla displays pop-up windows. If a user
choses to open a pop-up window whose URL is malicious javascript, the
script will be executed with elevated privileges. (CAN-2005-1153)

A bug was found in the way Mozilla installed search plugins. If a user
chooses to install a search plugin from a malicious site, the new plugin
could silently overwrite an existing plugin. This could allow the malicious
plugin to execute arbitrary code and stealm sensitive information.
(CAN-2005-1156 CAN-2005-1157)

Several bugs were found in the Mozilla javascript engine. A malicious web
page could leverage these issues to execute javascript with elevated
privileges or steal sensitive information. (CAN-2005-1154 CAN-2005-1155
CAN-2005-1159 CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/142390" id="142390">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144080" id="144080">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145606" id="145606">CAN-2005-0142 Opened attachments are temporarily saved world-readable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145607" id="145607">CAN-2005-0143 Secure site lock can be spoofed with a binary download</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145613" id="145613">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151722" id="151722">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152580" id="152580">CAN-2005-0578 Mozilla issues (CAN-2005-0232 CAN-2005-0527 CAN-2005-0231 CAN-2005-0584 CAN-2005-0585 CAN-2005-0586 CAN-2005-0588 CAN-2005-0590 CAN-2005-0591 CAN-2005-0593)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155117" id="155117">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384014" comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384016" comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384002" comment="mozilla is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384004" comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384012" comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384008" comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050386" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:386: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:386-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-386.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Vladimir V. Perepelitsa discovered a bug in the way Mozilla handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Doron Rosenberg discovered a bug in the way Mozilla displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges.
(CAN-2005-1153)

A bug was found in the way Mozilla handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. (CAN-2005-1154)

Michael Krax discovered a bug in the way Mozilla handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges.
(CAN-2005-1155)

Michael Krax discovered a bug in the way Mozilla installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and stealm sensitive
information. (CAN-2005-1156 CAN-2005-1157)

A bug was found in the way Mozilla validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Mozilla privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. (CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155116" id="155116">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386014" comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386016" comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386002" comment="mozilla is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386004" comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386012" comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386008" comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386022" comment="devhelp is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050387" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:387: cvs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:387-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-387.html" />
          <reference source="CVE" ref_id="CVE-2005-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0753.html" />
    
    <description>CVS (Concurrent Version System) is a version control system.

A buffer overflow bug was found in the way the CVS client processes version
and author information. If a user can be tricked into connecting to a
malicious CVS server, an attacker could execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0753 to this issue.

Additionally, a bug was found in which CVS freed an invalid pointer.
However, this issue does not appear to be exploitable.

All users of cvs should upgrade to this updated package, which includes a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0753.html">CVE-2005-0753</cve>
                <bugzilla href="http://bugzilla.redhat.com/155029" id="155029">CAN-2005-0753 multiple issues in cvs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387002" comment="cvs is earlier than 0:1.11.2-27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387005" comment="cvs is earlier than 0:1.11.17-7.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040004003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050392" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:392: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:392-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-392.html" />
          <reference source="CVE" ref_id="CVE-2005-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0755.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes RAM files.
An attacker could create a specially crafted RAM file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0755 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.4 and is not vulnerable to this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-20" />
        <updated date="2005-04-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0755.html">CVE-2005-0755</cve>
                <bugzilla href="http://bugzilla.redhat.com/155386" id="155386">CAN-2005-0755 HelixPlayer buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050392002" comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050393" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:393: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:393-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-393.html" />
          <reference source="CVE" ref_id="CVE-2005-1046" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1046.html" />
    
    <description>KDE is a graphical desktop environment for the X Window System. Konqueror
is the file manager for the K Desktop Environment. 

A source code audit performed by the KDE security team discovered several
vulnerabilities in the PCX and other image file format readers.

A buffer overflow was found in the kimgio library for KDE 3.4.0.  An
attacker could create a carefully crafted PCX image in such a way that it
would cause kimgio to execute arbitrary code when processing the image. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1046 to this issue.

All users of kdelibs should upgrade to these updated packages, which
contain a backported security patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1046.html">CVE-2005-1046</cve>
                <bugzilla href="http://bugzilla.redhat.com/152092" id="152092">CAN-2005-1046 PCX file integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393002" comment="kdelibs is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412007" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393004" comment="kdelibs-devel is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040412009" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050395" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:395: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-395.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management. 

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet that will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc that can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally, the following bugs have been fixed:
- The lmSensors are correctly recognized, snmp deamon no longer segfaults
- The larger swap partition sizes are correctly reported 
- Querying hrSWInstalledLastUpdateTime no longer crashes the snmp deamon
- Fixed error building ASN.1 representation
- The 64-bit network counters correctly wrap
- Large file systems are correctly handled
- Snmptrapd initscript correctly reads options from its configuration 
  file /etc/snmp/snmptrapd.options 
- Snmp deamon no longer crashes when restarted using the agentX 
  protocol
- snmp daemon now reports gigabit Ethernet speeds correctly
- MAC adresses are shown when requested instead of IP adresses

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/150084" id="150084">snmpd dies when getting enterprises.ucdavis.memory.memTotalSwap.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150199" id="150199">snmpd exits without a diagnostic: SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154798" id="154798">/etc/init.d/snmptrapd wrong order in setting variables...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155038" id="155038">x86_64: net-snmp dies when querying hrSWInstalledLastUpdateTime</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158769" id="158769">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163688" id="163688">CAN-2005-2177 net-snmp denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395004" comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023009" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395010" comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395008" comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023007" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395006" comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395002" comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040023003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050396" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:396: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:396-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-396.html" />
          <reference source="CVE" ref_id="CVE-2005-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2495.html" />
    
    <description>X.org is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow bugs were found in the way X.org parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue. 

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-13" />
        <updated date="2005-09-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2495.html">CVE-2005-2495</cve>
                <bugzilla href="http://bugzilla.redhat.com/166856" id="166856">CAN-2005-2495 multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396034" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396022" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396020" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396028" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396032" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396024" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396030" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396026" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050397" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:397: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-397.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
          <reference source="CVE" ref_id="CVE-2005-0806" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0806.html" />
    
    <description>Evolution is a GNOME-based collection of personal information management
(PIM) tools.

A bug was found in the way Evolution displays mail messages. It is possible
that an attacker could create a specially crafted mail message that when
opened by a victim causes Evolution to stop responding. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0806 to this issue.

A bug was also found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue.  On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default.  Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

All users of evolution should upgrade to these updated packages, which
include backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0806.html">CVE-2005-0806</cve>
                <bugzilla href="http://bugzilla.redhat.com/155375" id="155375">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155377" id="155377">CAN-2005-0806 DoS from mail message</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397002" comment="evolution is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397004" comment="evolution-devel is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050405" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:405: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:405-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-405.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way that it could execute arbitrary instructions when processed by PHP.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
 to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- The security fixes in RHSA-2004-687 to the "unserializer" code introduced
some performance issues.

- In the gd extension, the "imagecopymerge" function did not correctly
handle transparency.  The original image was being obscured in the
resultant image.

- In the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/145436" id="145436">PHP pages slow, HTTPD eating cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147808" id="147808">php curl open_basedir bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149873" id="149873">make PHP oci8 driver support Oracle Instant Client RPM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149946" id="149946">PHP GD ImageCopyMerge broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405014" comment="php-odbc is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405010" comment="php-mysql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405002" comment="php is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405012" comment="php-pgsql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405004" comment="php-devel is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405006" comment="php-imap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405008" comment="php-ldap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050406" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:406: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-406.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way it could execute arbitrary instructions when processed by PHP. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- some performance issues in the unserialize() function have been fixed

- the behaviour of the interpreter when handling integer overflow during
conversion of a floating variable to an integer has been reverted to match
the behaviour used upstream; the integer will now be wrapped rather than
truncated

- a fix for the virtual() function in the Apache httpd module which would
flush the response prematurely

- the hard-coded default "safe mode" setting is now "disabled" rather than
"enabled"; to match the default /etc/php.ini setting

- in the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/153108" id="153108">Error in configure prevents php SRPM rebuild on x86_64 w/ mssql module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406028" comment="php-gd is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406016" comment="php-odbc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392015" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406012" comment="php-mysql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406002" comment="php is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406022" comment="php-xmlrpc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406024" comment="php-mbstring is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406014" comment="php-pgsql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392013" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406004" comment="php-devel is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406026" comment="php-ncurses is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406018" comment="php-snmp is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406008" comment="php-imap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392007" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406006" comment="php-pear is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406020" comment="php-domxml is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406010" comment="php-ldap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20040392009" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050408" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:408: cyrus-imapd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:408-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-408.html" />
          <reference source="CVE" ref_id="CVE-2005-0546" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0546.html" />
    
    <description>The cyrus-imapd package contains the core of the Cyrus IMAP server.

Several buffer overflow bugs were found in cyrus-imapd. It is possible that
an authenticated malicious user could cause the imap server to crash.
Additionally, a peer news admin could potentially execute arbitrary code on
the imap server when news is received using the fetchnews command. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages, which
contain cyrus-imapd version 2.2.12 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0546.html">CVE-2005-0546</cve>
                <bugzilla href="http://bugzilla.redhat.com/149869" id="149869">CAN-2005-0546 multiple buffer overflows in cyrus-imapd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408006" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408007" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AN