<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions
	xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd"
	xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5"
	xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
      <oval:product_name>Marcus OVAL Generator</oval:product_name>
      <oval:schema_version>5.5</oval:schema_version>
      <oval:timestamp>2012-05-19T04:04:01</oval:timestamp>
  </generator>
  <definitions>
<definition id="oval:org.opensuse.security:def:20011267" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2001-1267</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2001-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1267" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 2506227b7bd914b11632b5701384104a -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030401" comment="tar less than 1.13.25-325.10"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036680" comment="tar less than 1.15.1-23.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030401" comment="tar less than 1.13.25-325.10"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036687" comment="tar less than 1.13.25-334"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20020029" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-0029</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0029" source="CVE"/>
	<description>
	Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6ac20f23c02d3d141a8010b05c2c933e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036688" comment="glibc-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036689" comment="glibc-devel-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036690" comment="glibc-devel less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036691" comment="glibc-locale less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036692" comment="glibc less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036693" comment="lsb-runtime less than 1.2-105"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036690" comment="glibc-devel less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036691" comment="glibc-locale less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036692" comment="glibc less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036693" comment="lsb-runtime less than 1.2-105"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036690" comment="glibc-devel less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036691" comment="glibc-locale less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036692" comment="glibc less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036693" comment="lsb-runtime less than 1.2-105"/>
			</criteria>
		</criteria></criteria>
	<!-- cdecd984b302ccff11f93eddbf4e1578 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036688" comment="glibc-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036694" comment="glibc-64bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036689" comment="glibc-devel-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036690" comment="glibc-devel less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036691" comment="glibc-locale less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036695" comment="glibc-x86 less than 2.2.5-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036692" comment="glibc less than 2.2.5-233"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036690" comment="glibc-devel less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036691" comment="glibc-locale less than 2.2.5-233"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036695" comment="glibc-x86 less than 2.2.5-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036692" comment="glibc less than 2.2.5-233"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20020180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-0180</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-0180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0180" source="CVE"/>
	<description>
	Buffer overflow in Webalizer 2.01-06, when configured to use reverse DNS lookups, allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname.Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
	</description>
 </metadata>
<!-- 4faf85ef372a18f6cfd084e3646c52cc -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036696" comment="webalizer less than 2.01-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036697" comment="webalizer less than 2.01-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036698" comment="webalizer less than 2.01-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036699" comment="webalizer less than 2.01-90"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036697" comment="webalizer less than 2.01-306"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20020181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-0181</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-0181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0181" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- dd8057372d0563f9ead39e3372c6242f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036700" comment="horde less than 1.2.6-552"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20020399" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-0399</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-0399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0399" source="CVE"/>
	<description>
	Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.Buffer overflow in X11 dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code while Ethereal is parsing keysyms.DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop.Vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (memory consumption).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2506227b7bd914b11632b5701384104a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030401" comment="tar less than 1.13.25-325.10"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036680" comment="tar less than 1.15.1-23.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030401" comment="tar less than 1.13.25-325.10"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036687" comment="tar less than 1.13.25-334"/>
		</criteria></criteria>
	<!-- cffcc0146fa6ba2fd6d7036a5d1643b8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030402" comment="tar less than 1.13.25-325.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030402" comment="tar less than 1.13.25-325.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036701" comment="tar less than 1.13.25-328"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20020875" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-0875</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-0875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0875" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- a9a83f6d7ec9e4ea540e640cfa5e1b66 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036702" comment="fam less than 2.6.9-29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036703" comment="fam less than 2.6.9-31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036704" comment="fam less than 2.6.9-41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036705" comment="fam less than 2.6.9-59"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036705" comment="fam less than 2.6.9-59"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021158" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1158</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1158" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 98a4d0bbd7fdc09cdce6b4b477f4fa4c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036706" comment="canna less than 3.5b2-134"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036707" comment="canna less than 3.5b2-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036708" comment="canna less than 3.5b2-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036709" comment="canna less than 3.5b2-534"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036709" comment="canna less than 3.5b2-534"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1159</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1159" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 98a4d0bbd7fdc09cdce6b4b477f4fa4c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036706" comment="canna less than 3.5b2-134"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036707" comment="canna less than 3.5b2-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036708" comment="canna less than 3.5b2-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036709" comment="canna less than 3.5b2-534"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036709" comment="canna less than 3.5b2-534"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021319" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1319</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1319" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3ac3c0c77688b9e756dc3ce824117331 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036710" comment="k_smp less than 2.4.19-145"/>
	</criteria>
	<!-- 45b103eb731fd1848be9fff9476ca823 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036711" comment="k_athlon less than 2.4.19-148"/>
	</criteria>
	<!-- 578aca634f389b976302011b1a1df8d0 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036712" comment="kernel-source less than 2.4.19.SuSE-104"/>
	</criteria>
	<!-- d3dcd5b159c406af42e6b50b67ec51bb -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036713" comment="k_deflt less than 2.4.19-155"/>
	</criteria>
	<!-- d93684f7e090729475d9487f0a84da6b -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036714" comment="k_debug less than 2.4.19-114"/>
	</criteria>
	<!-- e2cb5b42e9b7b13d23bb4cd649707236 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036715" comment="k_psmp less than 2.4.19-151"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021335" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1335</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1335" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
	</description>
 </metadata>
<!-- 2c74972becebb5ac58f8a60f15d67369 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036717" comment="w3m less than 0.3.1-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036718" comment="w3m less than 0.3.1-51"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036719" comment="w3m less than 0.3.1-52"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036720" comment="w3m less than 0.3.1-57"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036719" comment="w3m less than 0.3.1-52"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021336" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1336</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1336" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1336" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 45113a6473dd7f1cba7d5c28b55c720d -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036721" comment="vnc less than 3.3.3r2-234"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036722" comment="vnc less than 3.3.3r2-339"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036723" comment="vnc less than 3.3.3r2-504"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036723" comment="vnc less than 3.3.3r2-504"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021337" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1337</title>
	<affected family="unix">
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1337" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- cea49936f292ba8297049a5eb8da1eee -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036724" comment="sendmail-devel less than 8.12.6-32"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036725" comment="sendmail-devel less than 8.12.6-50"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036726" comment="sendmail-devel less than 8.12.6-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036727" comment="sendmail-devel less than 8.12.6-92"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036727" comment="sendmail-devel less than 8.12.6-92"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036726" comment="sendmail-devel less than 8.12.6-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036727" comment="sendmail-devel less than 8.12.6-92"/>
			</criteria>
		</criteria></criteria>
	<!-- de453c8319b6505d448075350f15aef5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036729" comment="sendmail less than 8.11.3-106"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036729" comment="sendmail less than 8.11.3-106"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036731" comment="sendmail less than 8.12.6-32"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036732" comment="sendmail less than 8.12.6-50"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036733" comment="sendmail less than 8.12.6-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036734" comment="sendmail less than 8.12.6-92"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036734" comment="sendmail less than 8.12.6-92"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036733" comment="sendmail less than 8.12.6-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036734" comment="sendmail less than 8.12.6-92"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021344" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1344</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1344" source="CVE"/>
	<description>
	Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
	</description>
 </metadata>
<!-- 74679c1131621ea84192a60dd6a49fc4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036735" comment="wget less than 1.8.2-108"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036736" comment="wget less than 1.8.2-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036737" comment="wget less than 1.8.2-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036738" comment="wget less than 1.8.2-83"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036736" comment="wget less than 1.8.2-146"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036735" comment="wget less than 1.8.2-108"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036736" comment="wget less than 1.8.2-146"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021348" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1348</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1348" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 2c74972becebb5ac58f8a60f15d67369 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036717" comment="w3m less than 0.3.1-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036718" comment="w3m less than 0.3.1-51"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036719" comment="w3m less than 0.3.1-52"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036720" comment="w3m less than 0.3.1-57"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036716" comment="w3m less than 0.3.1-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036719" comment="w3m less than 0.3.1-52"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021363" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1363</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1363" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- c8682399c09f0f2f4edc57b5b26db301 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036739" comment="libpng less than 2.1.0.10-57"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036740" comment="libpng less than 1.2.4-31"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036741" comment="libpng less than 1.2.4-39"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036742" comment="libpng less than 1.2.4-58"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036742" comment="libpng less than 1.2.4-58"/>
		</criteria></criteria>
	<!-- f9c1739372746401d3f80fddc3909d3d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036743" comment="libpng less than 2.1.0.10-61"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036744" comment="libpng less than 2.1.0.12-166"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2-vpn is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036743" comment="libpng less than 2.1.0.10-61"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036745" comment="libpng less than 1.2.4-113"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021365" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1365</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1365" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 7a343a052207c07bf213566ec26eb3a4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036746" comment="fetchmail less than 5.9.13-31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036747" comment="fetchmail less than 5.9.13-34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036748" comment="fetchmail less than 5.9.13-35"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036749" comment="fetchmail less than 5.9.13-54"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036749" comment="fetchmail less than 5.9.13-54"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021366" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1366</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1366" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021367" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1367</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1367" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021368" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1368</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1368" source="CVE"/>
	<description>
	Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021369" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1369</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1369" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1369" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021371" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1371</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1371" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021372" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1372</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1372" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021373" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1373</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1373" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 570b3857480f47251d8dab7483060f33 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036753" comment="mysql-shared less than 3.23.37-58"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036754" comment="mysql-shared less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036755" comment="mysql-shared less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036758" comment="mysql-shared less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- 9d5753c2054cfc6562bcc83884879fe5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036759" comment="mysql less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036760" comment="mysql less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036763" comment="mysql less than 3.23.52-45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036764" comment="mysql less than 3.23.52-47"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- a1e459fc5c6cf703254d34aefe8a0b43 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036765" comment="mysql less than 3.23.52-21"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036766" comment="mysql less than 3.23.52-29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
		</criteria></criteria>
	<!-- d11be3bae76d05abec7968bf6a75e1ef -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036768" comment="mysql-client less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036769" comment="mysql-client less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036772" comment="mysql-client less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- e8e7fee6b20f0a09bb20089bc479cdd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036773" comment="mysql-devel less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036774" comment="mysql-devel less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036777" comment="mysql-devel less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021374" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1374</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1374" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 570b3857480f47251d8dab7483060f33 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036753" comment="mysql-shared less than 3.23.37-58"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036754" comment="mysql-shared less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036755" comment="mysql-shared less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036758" comment="mysql-shared less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- 9d5753c2054cfc6562bcc83884879fe5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036759" comment="mysql less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036760" comment="mysql less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036763" comment="mysql less than 3.23.52-45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036764" comment="mysql less than 3.23.52-47"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- a1e459fc5c6cf703254d34aefe8a0b43 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036765" comment="mysql less than 3.23.52-21"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036766" comment="mysql less than 3.23.52-29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
		</criteria></criteria>
	<!-- d11be3bae76d05abec7968bf6a75e1ef -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036768" comment="mysql-client less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036769" comment="mysql-client less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036772" comment="mysql-client less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- e8e7fee6b20f0a09bb20089bc479cdd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036773" comment="mysql-devel less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036774" comment="mysql-devel less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036777" comment="mysql-devel less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021375" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1375</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1375" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 570b3857480f47251d8dab7483060f33 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036753" comment="mysql-shared less than 3.23.37-58"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036754" comment="mysql-shared less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036755" comment="mysql-shared less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036758" comment="mysql-shared less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- 9d5753c2054cfc6562bcc83884879fe5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036759" comment="mysql less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036760" comment="mysql less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036763" comment="mysql less than 3.23.52-45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036764" comment="mysql less than 3.23.52-47"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- a1e459fc5c6cf703254d34aefe8a0b43 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036765" comment="mysql less than 3.23.52-21"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036766" comment="mysql less than 3.23.52-29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
		</criteria></criteria>
	<!-- d11be3bae76d05abec7968bf6a75e1ef -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036768" comment="mysql-client less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036769" comment="mysql-client less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036772" comment="mysql-client less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- e8e7fee6b20f0a09bb20089bc479cdd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036773" comment="mysql-devel less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036774" comment="mysql-devel less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036777" comment="mysql-devel less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1376</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1376" source="CVE"/>
	<description>
	libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 570b3857480f47251d8dab7483060f33 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036753" comment="mysql-shared less than 3.23.37-58"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036754" comment="mysql-shared less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036755" comment="mysql-shared less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036758" comment="mysql-shared less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036756" comment="mysql-shared less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036757" comment="mysql-shared less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- 9d5753c2054cfc6562bcc83884879fe5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036759" comment="mysql less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036760" comment="mysql less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036763" comment="mysql less than 3.23.52-45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036764" comment="mysql less than 3.23.52-47"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036761" comment="mysql less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036762" comment="mysql less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- a1e459fc5c6cf703254d34aefe8a0b43 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036765" comment="mysql less than 3.23.52-21"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036766" comment="mysql less than 3.23.52-29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036767" comment="mysql less than 3.23.52-41"/>
		</criteria></criteria>
	<!-- d11be3bae76d05abec7968bf6a75e1ef -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036768" comment="mysql-client less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036769" comment="mysql-client less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036772" comment="mysql-client less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036770" comment="mysql-client less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036771" comment="mysql-client less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
	<!-- e8e7fee6b20f0a09bb20089bc479cdd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036773" comment="mysql-devel less than 3.23.52-23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036774" comment="mysql-devel less than 3.23.52-25"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036777" comment="mysql-devel less than 3.23.52-45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036775" comment="mysql-devel less than 3.23.52-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036776" comment="mysql-devel less than 3.23.52-44"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021383" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1383</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1383" source="CVE"/>
	<description>
	Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.openwebmail_init in Open WebMail 1.81 and earlier allows local users attackers to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021384" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1384</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1384" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- fd49e9dbce3ea25e111d005556e7cfb4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036750" comment="cups less than 1.1.15-43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036751" comment="cups less than 1.1.15-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036752" comment="cups less than 1.1.15-69"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021396" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1396</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1396" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- b4714f53d68dd3ff80ed4e191b9a92dd -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036778" comment="mod_php4-core less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036779" comment="mod_php4-core less than 4.2.2-45"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036780" comment="mod_php4-core less than 4.2.2-66"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036781" comment="mod_php4-core less than 4.2.2-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036782" comment="mod_php4-core less than 4.2.2-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036783" comment="mod_php4-servlet less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036784" comment="mod_php4-servlet less than 4.2.2-45"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036785" comment="mod_php4-servlet less than 4.2.2-66"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036786" comment="mod_php4-servlet less than 4.2.2-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036787" comment="mod_php4-servlet less than 4.2.2-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036788" comment="mod_php4 less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036789" comment="mod_php4 less than 4.2.2-45"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036790" comment="mod_php4 less than 4.2.2-66"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036791" comment="mod_php4 less than 4.2.2-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036792" comment="mod_php4 less than 4.2.2-81"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036778" comment="mod_php4-core less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036783" comment="mod_php4-servlet less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036788" comment="mod_php4 less than 4.2.2-165"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036778" comment="mod_php4-core less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036782" comment="mod_php4-core less than 4.2.2-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036783" comment="mod_php4-servlet less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036787" comment="mod_php4-servlet less than 4.2.2-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036788" comment="mod_php4 less than 4.2.2-165"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036792" comment="mod_php4 less than 4.2.2-81"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20021511" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-1511</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-1511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1511" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 2e683a5b4dc601512473c991c6d51c28 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036793" comment="vnc less than 3.3.3r2-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036794" comment="vnc less than 3.3.3r2-436"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036794" comment="vnc less than 3.3.3r2-436"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20022214" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-2214</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-2214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2214" source="CVE"/>
	<description>
	The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
	</description>
 </metadata>
<!-- d9cee2b4664d18e6170131684c7b9c0c -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036795" comment="mod_php4-core less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036796" comment="mod_php4-devel less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036797" comment="mod_php4-servlet less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036798" comment="mod_php4 less than 4.2.2-510"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20022215" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2002-2215</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2002-2215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2215" source="CVE"/>
	<description>
	The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function.
	</description>
 </metadata>
<!-- d9cee2b4664d18e6170131684c7b9c0c -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036795" comment="mod_php4-core less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036796" comment="mod_php4-devel less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036797" comment="mod_php4-servlet less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036798" comment="mod_php4 less than 4.2.2-510"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030015" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0015</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0015" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 0b3eaa4aeb3ff70a00380058bb3da906 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036799" comment="cvs less than 1.11.1p1-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036800" comment="cvs less than 1.11.1p1-235"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036801" comment="cvs less than 1.11.1p1-71"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036802" comment="cvs less than 1.11.1p1-93"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036800" comment="cvs less than 1.11.1p1-235"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030018" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0018</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0018" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d3b8661b6091d029efff7bd34c76ce8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036803" comment="k_psmp less than 2.4.19-346"/>
	</criteria>
	<!-- a91d13d9b8aa9ba852f3fd48b5a47993 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036804" comment="k_smp less than 2.4.19-346"/>
	</criteria>
	<!-- d69260901a5db56058a50e1a21e88429 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036805" comment="kernel-source less than 2.4.19.SuSE-346"/>
	</criteria>
	<!-- d8b8e10e2caef5026bf709bf4cd6672f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036806" comment="k_deflt less than 2.4.19-346"/>
	</criteria>
	<!-- debc85a657ac36c9b4b05c32fd479477 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036807" comment="k_athlon less than 2.4.19-346"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030020" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0020</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 26c3e83f9771093dfc1fecccbe79c9fe -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030403" comment="libapr0 less than 2.0.59-1.1"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032404" comment="apache2-devel less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032405" comment="apache2-doc less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032406" comment="apache2-example-pages less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032407" comment="apache2-prefork less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032408" comment="apache2-worker less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032409" comment="apache2 less than 2.0.59-1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030403" comment="libapr0 less than 2.0.59-1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- b0ad3afc1961097e6bb58010b7dba2c4 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036808" comment="apache-devel less than 1.3.19-153"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036809" comment="apache-devel less than 1.3.19-154"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036810" comment="apache-devel less than 1.3.20-85"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036812" comment="apache less than 1.3.19-153"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036813" comment="apache less than 1.3.19-154"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036814" comment="apache less than 1.3.20-85"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036816" comment="mod_ssl less than 2.8.3-74"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036817" comment="mod_ssl less than 2.8.3-75"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036818" comment="mod_ssl less than 2.8.4-85"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036820" comment="apache-devel less than 1.3.26-157"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036821" comment="apache less than 1.3.26-157"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036822" comment="mod_ssl less than 2.8.10-157"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030031" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0031</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0031" source="CVE"/>
	<description>
	Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.
	</description>
 </metadata>
<!-- 22464ea27fb14f7cef0c7be21d2a2252 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036823" comment="libmcrypt-devel less than 2.5.2-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036824" comment="libmcrypt-devel less than 2.5.2-26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036825" comment="libmcrypt-devel less than 2.5.2-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036827" comment="libmcrypt less than 2.5.2-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036828" comment="libmcrypt less than 2.5.2-26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036829" comment="libmcrypt less than 2.5.2-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030032" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0032</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0032" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 22464ea27fb14f7cef0c7be21d2a2252 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036823" comment="libmcrypt-devel less than 2.5.2-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036824" comment="libmcrypt-devel less than 2.5.2-26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036825" comment="libmcrypt-devel less than 2.5.2-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036827" comment="libmcrypt less than 2.5.2-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036828" comment="libmcrypt less than 2.5.2-26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036829" comment="libmcrypt less than 2.5.2-37"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036826" comment="libmcrypt-devel less than 2.5.2-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036830" comment="libmcrypt less than 2.5.2-48"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030033" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0033</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0033" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- ecf41c2c7beae8408b343a2f7f4bce8e -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036831" comment="snort less than 1.8.7b128-104"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036832" comment="snort less than 1.8.7b128-113"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036833" comment="snort less than 1.8.7b128-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036834" comment="snort less than 1.8.7b128-236"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036835" comment="snort less than 1.8.7b128-241"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036836" comment="snort less than 1.8.7b128-94"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036834" comment="snort less than 1.8.7b128-236"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036833" comment="snort less than 1.8.7b128-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036834" comment="snort less than 1.8.7b128-236"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036835" comment="snort less than 1.8.7b128-241"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030039" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0039</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0039" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 9fa3c8894df8b887f8ca15ee866e43c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036837" comment="dhcp-server less than 3.0.1rc9-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036838" comment="dhcp-server less than 3.0.1rc9-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036839" comment="dhcp-server less than 3.0.1rc9-54"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036840" comment="dhcp-server less than 3.0.1rc9-59"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036841" comment="dhcp-server less than 3.0.1rc9-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036842" comment="dhcp-server less than 3.0.1rc9-77"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036837" comment="dhcp-server less than 3.0.1rc9-109"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036837" comment="dhcp-server less than 3.0.1rc9-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036838" comment="dhcp-server less than 3.0.1rc9-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036842" comment="dhcp-server less than 3.0.1rc9-77"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030078" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0078</title>
	<affected family="unix">
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0078" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4b5e1a52a4e98f479c19123b973042b9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036843" comment="openssl less than 0.9.6a-78"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036843" comment="openssl less than 0.9.6a-78"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036844" comment="openssl less than 0.9.6g-22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036845" comment="openssl less than 0.9.6g-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036846" comment="openssl less than 0.9.6g-38"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036847" comment="openssl less than 0.9.6g-43"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036848" comment="openssl less than 0.9.6g-55"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036848" comment="openssl less than 0.9.6g-55"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036847" comment="openssl less than 0.9.6g-43"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036848" comment="openssl less than 0.9.6g-55"/>
			</criteria>
		</criteria></criteria>
	<!-- d7cba6a9980ab28d14a3b2324d17477f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036849" comment="openssl-devel less than 0.9.6g-22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036850" comment="openssl-devel less than 0.9.6g-24"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036851" comment="openssl-devel less than 0.9.6g-38"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036852" comment="openssl-devel less than 0.9.6g-43"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036853" comment="openssl-devel less than 0.9.6g-55"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036853" comment="openssl-devel less than 0.9.6g-55"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036852" comment="openssl-devel less than 0.9.6g-43"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036853" comment="openssl-devel less than 0.9.6g-55"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030081" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0081</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0081" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- bf43fc249336e0e0ad1cd275e3086074 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036854" comment="ethereal less than 0.9.6-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036855" comment="ethereal less than 0.9.6-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036856" comment="ethereal less than 0.9.6-59"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036857" comment="ethereal less than 0.9.6-64"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036858" comment="ethereal less than 0.9.6-89"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036855" comment="ethereal less than 0.9.6-152"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036854" comment="ethereal less than 0.9.6-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036855" comment="ethereal less than 0.9.6-152"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0085</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085" source="CVE"/>
	<description>
	Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 47921afc46400c5c364d23e38a052f1e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036859" comment="samba-client less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036860" comment="samba-client less than 2.2.5-160"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036861" comment="samba-client less than 2.2.5-68"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036862" comment="samba-client less than 2.2.5-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036863" comment="samba-client less than 2.2.5-90"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036860" comment="samba-client less than 2.2.5-160"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036859" comment="samba-client less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036860" comment="samba-client less than 2.2.5-160"/>
			</criteria>
		</criteria></criteria>
	<!-- 65165300e6b2178c9b948562ba15637d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036864" comment="samba-client less than 2.2.5-119"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036866" comment="samba-client less than 2.2.5-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036867" comment="samba-client less than 2.2.5-74"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036868" comment="samba-client less than 2.2.5-92"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036864" comment="samba-client less than 2.2.5-119"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
			</criteria>
		</criteria></criteria>
	<!-- 93470b3242200a38b416c74e5542944e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036869" comment="samba less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036871" comment="samba less than 2.2.5-68"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036872" comment="samba less than 2.2.5-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036873" comment="samba less than 2.2.5-90"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036869" comment="samba less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030086" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0086</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0086" source="CVE"/>
	<description>
	The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65165300e6b2178c9b948562ba15637d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036864" comment="samba-client less than 2.2.5-119"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036866" comment="samba-client less than 2.2.5-70"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036867" comment="samba-client less than 2.2.5-74"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036868" comment="samba-client less than 2.2.5-92"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036864" comment="samba-client less than 2.2.5-119"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036865" comment="samba-client less than 2.2.5-166"/>
			</criteria>
		</criteria></criteria>
	<!-- 93470b3242200a38b416c74e5542944e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036869" comment="samba less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036871" comment="samba less than 2.2.5-68"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036872" comment="samba less than 2.2.5-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036873" comment="samba less than 2.2.5-90"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036869" comment="samba less than 2.2.5-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036870" comment="samba less than 2.2.5-160"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030102" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0102</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0102" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 1c5c1f136d4986616e48f2a8c000e98c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036874" comment="file less than 3.33-85"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036875" comment="file less than 3.37-163"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036876" comment="file less than 3.37-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036877" comment="file less than 3.37-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036878" comment="file less than 3.37-82"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036879" comment="file less than 3.37-93"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036877" comment="file less than 3.37-206"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036876" comment="file less than 3.37-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036877" comment="file less than 3.37-206"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030108" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0108</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0108" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 1b7bf424e2126adbbf2086824ce24248 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036880" comment="tcpdump less than 3.4a6-386"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036881" comment="tcpdump less than 3.7.1-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036882" comment="tcpdump less than 3.7.1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036883" comment="tcpdump less than 3.7.1-196"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036884" comment="tcpdump less than 3.7.1-71"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036885" comment="tcpdump less than 3.7.1-87"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036883" comment="tcpdump less than 3.7.1-196"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036882" comment="tcpdump less than 3.7.1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036883" comment="tcpdump less than 3.7.1-196"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030127" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0127</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0127" source="CVE"/>
	<description>
	The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 000b37546a3c86d4b9084a07dd7cf10a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036886" comment="kernel-iseries64 less than 2.4.19-194"/>
	</criteria>
	<!-- 3dd6d0bf897a0f13e2eb3d7349462273 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036887" comment="kernel-source less than 2.4.19.SuSE-102"/>
	</criteria>
	<!-- 4c7cc6ad5e5e5d74b3f2c2843d572e1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036888" comment="kernel-source less than 2.4.19.SuSE-70"/>
	</criteria>
	<!-- 51e0c2e11ced11e888da7470bf4073ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036889" comment="kernel-ppc64 less than 2.4.19-186"/>
	</criteria>
	<!-- 572ed6c9ce7d1b46a25fe06d664f9b06 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036890" comment="kernel-source less than 2.4.19.SuSE-175"/>
	</criteria>
	<!-- 621490f050affc2af03c6d69cd518cb8 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036891" comment="k_psmp less than 2.4.19-263"/>
	</criteria>
	<!-- 8376e89e202b4ff8a110e46f408dcc3a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036892" comment="k_athlon less than 2.4.19-263"/>
	</criteria>
	<!-- a868dbbfc53ae1b4716300f1bdc57f31 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036893" comment="k_deflt less than 2.4.19-70"/>
	</criteria>
	<!-- a9a055b71c8c9948ae106b0fce409602 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036894" comment="kernel-ppc64 less than 2.4.19-184"/>
	</criteria>
	<!-- b5e55e932b9ad385d0d39a949fce3b6d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036895" comment="k_smp less than 2.4.19-257"/>
	</criteria>
	<!-- e26dc57e4fa1e85c89683ce89b1ad2b1 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036896" comment="k_debug less than 2.4.19-213"/>
	</criteria>
	<!-- f54ead2affbc4ca9a638647432f0f01b -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036897" comment="k_deflt less than 2.4.19-274"/>
	</criteria>
	<!-- f78f14b241d39f680d3bbde92a35cc83 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036898" comment="kernel-iseries64 less than 2.4.19-191"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030131" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0131</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0131" source="CVE"/>
	<description>
	The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
	</description>
 </metadata>
<!-- 2d2d8d084dc6f07d2f6b2c53525b8240 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036899" comment="openssl less than 0.9.6a-80"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036900" comment="openssl less than 0.9.6g-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036901" comment="openssl less than 0.9.6g-27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036902" comment="openssl less than 0.9.6g-41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036903" comment="openssl less than 0.9.6g-46"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036904" comment="openssl less than 0.9.6g-64"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036904" comment="openssl less than 0.9.6g-64"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036903" comment="openssl less than 0.9.6g-46"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036904" comment="openssl less than 0.9.6g-64"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030136" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0136</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
	</affected>
	<reference ref_id="CVE-2003-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0136" source="CVE"/>
	<description>
	psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.
	</description>
 </metadata>
<!-- 1204b033a81823dee656103c6cd6f011 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036905" comment="lprng less than 3.8.12-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036906" comment="lprng less than 3.8.12-50"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036907" comment="lprng less than 3.8.12-60"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036908" comment="lprng less than 3.8.12-61"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036909" comment="lprng less than 3.8.12-92"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036910" comment="lprng less than 3.8.12-99"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036909" comment="lprng less than 3.8.12-92"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030140" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0140</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0140" source="CVE"/>
	<description>
	Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.
	</description>
 </metadata>
<!-- 1b8b442d23ac56b71fc283f831748976 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036911" comment="mutt less than 1.3.16i-92"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036912" comment="mutt less than 1.4i-117"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036913" comment="mutt less than 1.4i-160"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036914" comment="mutt less than 1.4i-217"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036915" comment="mutt less than 1.4i-88"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036916" comment="mutt less than 1.4i-95"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036914" comment="mutt less than 1.4i-217"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036913" comment="mutt less than 1.4i-160"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036914" comment="mutt less than 1.4i-217"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030143" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0143</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0143" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- dc0a4a4e5e7f84b3cd339a0c25131177 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036917" comment="qpopper less than 4.0.4-112"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036918" comment="qpopper less than 4.0.4-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036919" comment="qpopper less than 4.0.4-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036920" comment="qpopper less than 4.0.4-69"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036921" comment="qpopper less than 4.0.4-91"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036918" comment="qpopper less than 4.0.4-132"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036917" comment="qpopper less than 4.0.4-112"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036918" comment="qpopper less than 4.0.4-132"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030146" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0146</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
	</affected>
	<reference ref_id="CVE-2003-0146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0146" source="CVE"/>
	<description>
	Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 47327de029b7f0eaae66e68df6489e5e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036922" comment="libnetpbm less than 1.0.0-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036923" comment="libnetpbm less than 1.0.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036924" comment="libnetpbm less than 1.0.0-283"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036925" comment="libnetpbm less than 1.0.0-294"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036926" comment="libnetpbm less than 1.0.0-387"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036926" comment="libnetpbm less than 1.0.0-387"/>
		</criteria></criteria>
	<!-- 54a09a43906c79424692a0cb9aa9134f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036927" comment="netpbm less than 10.5-40"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036928" comment="netpbm less than 10.5-56"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036929" comment="netpbm less than 10.5-57"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036930" comment="netpbm less than 10.5-66"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036930" comment="netpbm less than 10.5-66"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030161" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0161</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0161" source="CVE"/>
	<description>
	The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 63ef3602dad4c0eeb0c19cf83808746b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036931" comment="sendmail less than 8.11.3-108"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036932" comment="sendmail less than 8.12.6-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036933" comment="sendmail less than 8.12.6-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036934" comment="sendmail less than 8.12.6-37"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036935" comment="sendmail less than 8.12.6-54"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036936" comment="sendmail less than 8.12.6-74"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036932" comment="sendmail less than 8.12.6-109"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036932" comment="sendmail less than 8.12.6-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036936" comment="sendmail less than 8.12.6-74"/>
			</criteria>
		</criteria></criteria>
	<!-- e8426b8e8a7ba6510b9b8e35deec594a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036937" comment="sendmail-devel less than 8.12.6-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036938" comment="sendmail-devel less than 8.12.6-36"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036939" comment="sendmail-devel less than 8.12.6-37"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036940" comment="sendmail-devel less than 8.12.6-54"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036941" comment="sendmail-devel less than 8.12.6-74"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036937" comment="sendmail-devel less than 8.12.6-109"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036937" comment="sendmail-devel less than 8.12.6-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036941" comment="sendmail-devel less than 8.12.6-74"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030190" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0190</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2003-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0190" source="CVE"/>
	<description>
	OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4af044adfe942bf6b49a0bdd3e5e5952 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030404" comment="openssh less than 3.8p1-37.17"/>
	</criteria>
	<!-- 752421e658dda743b9500849b697497d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030404" comment="openssh less than 3.8p1-37.17"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030195" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0195</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0195" source="CVE"/>
	<description>
	CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 83ab79c13205b22859df65400e64b2f3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036942" comment="cups-client less than 1.1.15-98"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036943" comment="cups-libs less than 1.1.15-98"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036944" comment="cups less than 1.1.15-98"/>
		</criteria>
	</criteria>
	<!-- e0bfd06f68f9f9cf5fe8b607bff99887 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036945" comment="cups-client less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036946" comment="cups-client less than 1.1.15-55"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036947" comment="cups-client less than 1.1.15-56"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036948" comment="cups-client less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036949" comment="cups-client less than 1.1.15-67"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036942" comment="cups-client less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036950" comment="cups-devel less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036951" comment="cups-devel less than 1.1.15-55"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036952" comment="cups-devel less than 1.1.15-56"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036953" comment="cups-devel less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036954" comment="cups-devel less than 1.1.15-67"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036955" comment="cups-devel less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036956" comment="cups-libs less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036957" comment="cups-libs less than 1.1.15-55"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036958" comment="cups-libs less than 1.1.15-56"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036959" comment="cups-libs less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036960" comment="cups-libs less than 1.1.15-67"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036943" comment="cups-libs less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036961" comment="cups less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036962" comment="cups less than 1.1.15-55"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036963" comment="cups less than 1.1.15-56"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036964" comment="cups less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036965" comment="cups less than 1.1.15-67"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036944" comment="cups less than 1.1.15-98"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036942" comment="cups-client less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036955" comment="cups-devel less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036943" comment="cups-libs less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036944" comment="cups less than 1.1.15-98"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036945" comment="cups-client less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036948" comment="cups-client less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036942" comment="cups-client less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036950" comment="cups-devel less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036953" comment="cups-devel less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036955" comment="cups-devel less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036956" comment="cups-libs less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036959" comment="cups-libs less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036943" comment="cups-libs less than 1.1.15-98"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036961" comment="cups less than 1.1.15-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036964" comment="cups less than 1.1.15-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036944" comment="cups less than 1.1.15-98"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0201</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201" source="CVE"/>
	<description>
	Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 727fa1506b3debe49829772807f466fa -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036966" comment="samba less than 2.2.5-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036967" comment="samba less than 2.2.5-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036968" comment="samba less than 2.2.5-73"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036969" comment="samba less than 2.2.5-76"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036970" comment="samba less than 2.2.5-94"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036967" comment="samba less than 2.2.5-177"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036966" comment="samba less than 2.2.5-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036967" comment="samba less than 2.2.5-177"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030204" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0204</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0204" source="CVE"/>
	<description>
	KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
	</description>
 </metadata>
<!-- 6032c9a5f7eac24da023436a3ac161cd -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036971" comment="kdebase3-kdm less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036972" comment="kdebase3-kdm less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036973" comment="kdebase3-kdm less than 3.0.3-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036974" comment="kdebase3-kdm less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036975" comment="kdebase3-kdm less than 3.0.3-88"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036976" comment="kdebase3-kdm less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036977" comment="kdebase3-konqueror less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036978" comment="kdebase3-konqueror less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036979" comment="kdebase3-konqueror less than 3.0.3-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036980" comment="kdebase3-konqueror less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036981" comment="kdebase3-konqueror less than 3.0.3-88"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036982" comment="kdebase3-konqueror less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036983" comment="kdebase3-ksysguardd less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036984" comment="kdebase3-ksysguardd less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036985" comment="kdebase3-ksysguardd less than 3.0.3-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036986" comment="kdebase3-ksysguardd less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036987" comment="kdebase3-ksysguardd less than 3.0.3-88"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036988" comment="kdebase3-ksysguardd less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036989" comment="kdebase3 less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036990" comment="kdebase3 less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036991" comment="kdebase3 less than 3.0.3-63"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036992" comment="kdebase3 less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036993" comment="kdebase3 less than 3.0.3-88"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036994" comment="kdebase3 less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036995" comment="kdelibs3-cups less than 3.0.3-125"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036996" comment="kdelibs3-cups less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036997" comment="kdelibs3-cups less than 3.0.3-52"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036998" comment="kdelibs3-cups less than 3.0.3-53"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036999" comment="kdelibs3-cups less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037000" comment="kdelibs3-cups less than 3.0.3-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037001" comment="kdelibs3 less than 3.0.3-125"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037002" comment="kdelibs3 less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037003" comment="kdelibs3 less than 3.0.3-52"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037004" comment="kdelibs3 less than 3.0.3-53"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037005" comment="kdelibs3 less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037006" comment="kdelibs3 less than 3.0.3-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037007" comment="kdenetwork3-mail less than 3.0.3-119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037008" comment="kdenetwork3-mail less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037009" comment="kdenetwork3-mail less than 3.0.3-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037010" comment="kdenetwork3-mail less than 3.0.3-51"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037011" comment="kdenetwork3-mail less than 3.0.3-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037012" comment="kdenetwork3-mail less than 3.0.3-77"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037013" comment="kdenetwork3 less than 3.0.3-119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037014" comment="kdenetwork3 less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037015" comment="kdenetwork3 less than 3.0.3-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037016" comment="kdenetwork3 less than 3.0.3-51"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037017" comment="kdenetwork3 less than 3.0.3-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037018" comment="kdenetwork3 less than 3.0.3-77"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037019" comment="kdeutils3 less than 3.0.3-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037020" comment="kdeutils3 less than 3.0.3-159"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037021" comment="kdeutils3 less than 3.0.3-49"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037022" comment="kdeutils3 less than 3.0.3-67"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037023" comment="kdeutils3 less than 3.0.3-78"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036972" comment="kdebase3-kdm less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036978" comment="kdebase3-konqueror less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036984" comment="kdebase3-ksysguardd less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036990" comment="kdebase3 less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036996" comment="kdelibs3-cups less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037002" comment="kdelibs3 less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037008" comment="kdenetwork3-mail less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037014" comment="kdenetwork3 less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037020" comment="kdeutils3 less than 3.0.3-159"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036971" comment="kdebase3-kdm less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036972" comment="kdebase3-kdm less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036976" comment="kdebase3-kdm less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036977" comment="kdebase3-konqueror less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036978" comment="kdebase3-konqueror less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036982" comment="kdebase3-konqueror less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036983" comment="kdebase3-ksysguardd less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036984" comment="kdebase3-ksysguardd less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036988" comment="kdebase3-ksysguardd less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036989" comment="kdebase3 less than 3.0.3-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036990" comment="kdebase3 less than 3.0.3-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036994" comment="kdebase3 less than 3.0.3-93"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036995" comment="kdelibs3-cups less than 3.0.3-125"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036996" comment="kdelibs3-cups less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036999" comment="kdelibs3-cups less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037001" comment="kdelibs3 less than 3.0.3-125"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037002" comment="kdelibs3 less than 3.0.3-137"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037005" comment="kdelibs3 less than 3.0.3-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037007" comment="kdenetwork3-mail less than 3.0.3-119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037008" comment="kdenetwork3-mail less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037011" comment="kdenetwork3-mail less than 3.0.3-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037013" comment="kdenetwork3 less than 3.0.3-119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037014" comment="kdenetwork3 less than 3.0.3-152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037017" comment="kdenetwork3 less than 3.0.3-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037019" comment="kdeutils3 less than 3.0.3-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037020" comment="kdeutils3 less than 3.0.3-159"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037022" comment="kdeutils3 less than 3.0.3-67"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0209</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0209" source="CVE"/>
	<description>
	Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 1a2ca3d760aa4382fba5dc7f283df62a -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037024" comment="snort less than 1.8.7b128-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037025" comment="snort less than 1.8.7b128-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037026" comment="snort less than 1.8.7b128-224"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037027" comment="snort less than 1.8.7b128-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037028" comment="snort less than 1.8.7b128-86"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037029" comment="snort less than 1.8.7b128-97"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037026" comment="snort less than 1.8.7b128-224"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037025" comment="snort less than 1.8.7b128-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037026" comment="snort less than 1.8.7b128-224"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037027" comment="snort less than 1.8.7b128-226"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0211</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0211" source="CVE"/>
	<description>
	Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.
	</description>
 </metadata>
<!-- cfd8039bc71e4927325f8c721d9e27f2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037030" comment="xinetd less than 2.3.11-15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037031" comment="xinetd less than 2.3.11-18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037032" comment="xinetd less than 2.3.11-22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037033" comment="xinetd less than 2.3.11-26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037034" comment="xinetd less than 2.3.11-9"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037033" comment="xinetd less than 2.3.11-26"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037032" comment="xinetd less than 2.3.11-22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037033" comment="xinetd less than 2.3.11-26"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030213" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0213</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0213" source="CVE"/>
	<description>
	ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 03e42006734152923d8f7f722b722baf -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037035" comment="pptpd less than 1.1.2-134"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037036" comment="pptpd less than 1.1.2-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037037" comment="pptpd less than 1.1.2-179"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037038" comment="pptpd less than 1.1.2-262"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037039" comment="pptpd less than 1.1.2-307"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037040" comment="pptpd less than 1.1.2-412"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037040" comment="pptpd less than 1.1.2-412"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037036" comment="pptpd less than 1.1.2-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037039" comment="pptpd less than 1.1.2-307"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037040" comment="pptpd less than 1.1.2-412"/>
			</criteria>
		</criteria></criteria>
	<!-- 1afc4a72c4b15777b405925476da4732 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037041" comment="ppp less than 2.4.1-151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037042" comment="ppp less than 2.4.1-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037043" comment="ppp less than 2.4.1-277"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037044" comment="ppp less than 2.4.1-284"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037045" comment="ppp less than 2.4.1-351"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037046" comment="ppp less than 2.4.1-94"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037045" comment="ppp less than 2.4.1-351"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037042" comment="ppp less than 2.4.1-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037044" comment="ppp less than 2.4.1-284"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037045" comment="ppp less than 2.4.1-351"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030244" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0244</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
	</affected>
	<reference ref_id="CVE-2003-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0244" source="CVE"/>
	<description>
	The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1438416d547a7151418d5c7f589035e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037047" comment="kernel-iseries64 less than 2.4.19-229"/>
	</criteria>
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 418166c4e22b91bfe7adee633864d7a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037050" comment="kernel-ppc64 less than 2.4.19-219"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- be4afd9f858aef4ef4e5bdbb1668cc1d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037053" comment="kernel-source less than 2.4.19.SuSE-125"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030247" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0247</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
	</affected>
	<reference ref_id="CVE-2003-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0247" source="CVE"/>
	<description>
	Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1438416d547a7151418d5c7f589035e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037047" comment="kernel-iseries64 less than 2.4.19-229"/>
	</criteria>
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 418166c4e22b91bfe7adee633864d7a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037050" comment="kernel-ppc64 less than 2.4.19-219"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- be4afd9f858aef4ef4e5bdbb1668cc1d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037053" comment="kernel-source less than 2.4.19.SuSE-125"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030252" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0252</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0252" source="CVE"/>
	<description>
	Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
	</description>
 </metadata>
<!-- 8ad601c1bd93ee96c906254272c31fc0 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037056" comment="nfs-utils less than 0.3.1-111"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037057" comment="nfs-utils less than 1.0.1-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037058" comment="nfs-utils less than 1.0.1-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037059" comment="nfs-utils less than 1.0.1-65"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037060" comment="nfs-utils less than 1.0.1-67"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037061" comment="nfs-utils less than 1.0.1-78"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037062" comment="nfs-utils less than 1.0.1-79"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037057" comment="nfs-utils less than 1.0.1-109"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037057" comment="nfs-utils less than 1.0.1-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037058" comment="nfs-utils less than 1.0.1-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037062" comment="nfs-utils less than 1.0.1-79"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030282" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0282</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282" source="CVE"/>
	<description>
	Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- f419fccf9faafb73541b865448cef84a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037063" comment="unzip less than 5.42-203"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037064" comment="unzip less than 5.50-165"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037065" comment="unzip less than 5.50-168"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037066" comment="unzip less than 5.50-204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037067" comment="unzip less than 5.50-207"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037068" comment="unzip less than 5.50-245"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037069" comment="unzip less than 5.50-253"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037068" comment="unzip less than 5.50-245"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037066" comment="unzip less than 5.50-204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037068" comment="unzip less than 5.50-245"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037069" comment="unzip less than 5.50-253"/>
			</criteria>
		</criteria></criteria>
	<!-- f57f2609ffcbac52ae812293818fb8e3 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037070" comment="unzip less than 5.42-200"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037071" comment="unzip less than 5.50-123"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037072" comment="unzip less than 5.50-128"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037073" comment="unzip less than 5.50-160"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037074" comment="unzip less than 5.50-161"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037075" comment="unzip less than 5.50-194"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037076" comment="unzip less than 5.50-203"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037075" comment="unzip less than 5.50-194"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037074" comment="unzip less than 5.50-161"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037075" comment="unzip less than 5.50-194"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037076" comment="unzip less than 5.50-203"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0297</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0297" source="CVE"/>
	<description>
	c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
	</description>
 </metadata>
<!-- 4358715f8310f460851062ecb69b64f8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037077" comment="pine less than 4.44-319"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030354" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0354</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0354" source="CVE"/>
	<description>
	Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.
	</description>
 </metadata>
<!-- 121ef4aef8fe054aa5683e961a656fa5 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037078" comment="ghostscript-library less than 7.05.3-108"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037079" comment="ghostscript-library less than 7.05.3-162"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037080" comment="ghostscript-library less than 7.05.3-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037081" comment="ghostscript-library less than 7.05.3-74"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037082" comment="ghostscript-library less than 7.05.3-75"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037083" comment="ghostscript-library less than 7.05.3-92"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037079" comment="ghostscript-library less than 7.05.3-162"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037078" comment="ghostscript-library less than 7.05.3-108"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037079" comment="ghostscript-library less than 7.05.3-162"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037080" comment="ghostscript-library less than 7.05.3-167"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030356" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0356</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356" source="CVE"/>
	<description>
	Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.
	</description>
 </metadata>
<!-- 805c1ae79eac23318a09f0f7887f437b -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037084" comment="ethereal less than 0.9.6-101"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037085" comment="ethereal less than 0.9.6-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037086" comment="ethereal less than 0.9.6-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037088" comment="ethereal less than 0.9.6-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037089" comment="ethereal less than 0.9.6-74"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037085" comment="ethereal less than 0.9.6-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037086" comment="ethereal less than 0.9.6-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030357" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0357</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0357" source="CVE"/>
	<description>
	Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.
	</description>
 </metadata>
<!-- 805c1ae79eac23318a09f0f7887f437b -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037084" comment="ethereal less than 0.9.6-101"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037085" comment="ethereal less than 0.9.6-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037086" comment="ethereal less than 0.9.6-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037088" comment="ethereal less than 0.9.6-68"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037089" comment="ethereal less than 0.9.6-74"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037085" comment="ethereal less than 0.9.6-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037086" comment="ethereal less than 0.9.6-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037087" comment="ethereal less than 0.9.6-187"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030428" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0428</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0428" source="CVE"/>
	<description>
	Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.
	</description>
 </metadata>
<!-- 783e96c0180171d85ca7bb806adba5be -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037090" comment="ethereal less than 0.9.6-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037094" comment="ethereal less than 0.9.6-79"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037095" comment="ethereal less than 0.9.6-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030429" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0429</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0429" source="CVE"/>
	<description>
	The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.
	</description>
 </metadata>
<!-- 783e96c0180171d85ca7bb806adba5be -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037090" comment="ethereal less than 0.9.6-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037094" comment="ethereal less than 0.9.6-79"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037095" comment="ethereal less than 0.9.6-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030430" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0430</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0430" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0430" source="CVE"/>
	<description>
	The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.
	</description>
 </metadata>
<!-- 783e96c0180171d85ca7bb806adba5be -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037090" comment="ethereal less than 0.9.6-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037094" comment="ethereal less than 0.9.6-79"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037095" comment="ethereal less than 0.9.6-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030431" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0431</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0431" source="CVE"/>
	<description>
	The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.
	</description>
 </metadata>
<!-- 783e96c0180171d85ca7bb806adba5be -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037090" comment="ethereal less than 0.9.6-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037094" comment="ethereal less than 0.9.6-79"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037095" comment="ethereal less than 0.9.6-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030432" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0432</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0432" source="CVE"/>
	<description>
	Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.
	</description>
 </metadata>
<!-- 783e96c0180171d85ca7bb806adba5be -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037090" comment="ethereal less than 0.9.6-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037094" comment="ethereal less than 0.9.6-79"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037095" comment="ethereal less than 0.9.6-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037091" comment="ethereal less than 0.9.6-120"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037092" comment="ethereal less than 0.9.6-184"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037093" comment="ethereal less than 0.9.6-202"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030442" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0442</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0442" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
	</description>
 </metadata>
<!-- 105100443950995a8cecd29f4983ae43 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037096" comment="mod_php4-core less than 4.2.2-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037097" comment="mod_php4-core less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037098" comment="mod_php4-core less than 4.2.2-131"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037100" comment="mod_php4-core less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037101" comment="mod_php4-core less than 4.2.2-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037102" comment="mod_php4-devel less than 4.2.2-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037103" comment="mod_php4-devel less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037104" comment="mod_php4-devel less than 4.2.2-131"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037106" comment="mod_php4-devel less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037107" comment="mod_php4-devel less than 4.2.2-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037108" comment="mod_php4-servlet less than 4.2.2-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037109" comment="mod_php4-servlet less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037110" comment="mod_php4-servlet less than 4.2.2-131"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037112" comment="mod_php4-servlet less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037113" comment="mod_php4-servlet less than 4.2.2-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037114" comment="mod_php4 less than 4.2.2-109"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037115" comment="mod_php4 less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037116" comment="mod_php4 less than 4.2.2-131"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037118" comment="mod_php4 less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037119" comment="mod_php4 less than 4.2.2-84"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037097" comment="mod_php4-core less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037100" comment="mod_php4-core less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037103" comment="mod_php4-devel less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037106" comment="mod_php4-devel less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037109" comment="mod_php4-servlet less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037112" comment="mod_php4-servlet less than 4.2.2-359"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037115" comment="mod_php4 less than 4.2.2-121"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037118" comment="mod_php4 less than 4.2.2-359"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030455" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0455</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
	</affected>
	<reference ref_id="CVE-2003-0455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0455" source="CVE"/>
	<description>
	The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.
	</description>
 </metadata>
<!-- a478fb7b625c6fba965a60d13e368014 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037120" comment="ImageMagick less than 5.4.7-192"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037121" comment="ImageMagick less than 5.4.7-194"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030459" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0459</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0459" source="CVE"/>
	<description>
	KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
	</description>
 </metadata>
<!-- 42652abaf7c3884401055dee7a05d265 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037122" comment="kdelibs3 less than 3.0.3-101"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037123" comment="kdelibs3 less than 3.0.3-115"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037124" comment="kdelibs3 less than 3.0.3-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037125" comment="kdelibs3 less than 3.0.3-176"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037126" comment="kdelibs3 less than 3.0.3-86"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037127" comment="kdelibs3 less than 3.0.3-88"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037128" comment="kdelibs3 less than 3.1.1-113"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037125" comment="kdelibs3 less than 3.0.3-176"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037122" comment="kdelibs3 less than 3.0.3-101"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037124" comment="kdelibs3 less than 3.0.3-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037125" comment="kdelibs3 less than 3.0.3-176"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030462" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0462</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
	</affected>
	<reference ref_id="CVE-2003-0462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0462" source="CVE"/>
	<description>
	A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030464" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0464</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux School Server for i386</platform>
	</affected>
	<reference ref_id="CVE-2003-0464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0464" source="CVE"/>
	<description>
	The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d3d9eb157fcbc2cecbf5e43de2e6ba77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037129" comment="alice-compat less than 0.21-207"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037130" comment="autoyast2 less than 2.6.44-27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037131" comment="mkisofs less than 1.11.a28-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037132" comment="perl-XML-DOM less than 1.39-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037133" comment="perl-XML-Generator less than 0.91-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037134" comment="perl-XML-RegExp less than 0.03-422"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037135" comment="syslinux less than 1.62-531"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037136" comment="xntp-doc less than 4.1.1-331"/>
		</criteria>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030468" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0468</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0468" source="CVE"/>
	<description>
	Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
	</description>
 </metadata>
<!-- ab8d2749cf10fb04d6eadd79b5b391b2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037137" comment="postfix less than 1.1.12-12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037138" comment="postfix less than 1.1.12-13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037139" comment="postfix less than 1.1.12-3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037140" comment="postfix less than 1.1.12-4"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037141" comment="postfix less than 1.1.12-11"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037137" comment="postfix less than 1.1.12-12"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037137" comment="postfix less than 1.1.12-12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037138" comment="postfix less than 1.1.12-13"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030476" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0476</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux School Server for i386</platform>
	</affected>
	<reference ref_id="CVE-2003-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0476" source="CVE"/>
	<description>
	The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d3d9eb157fcbc2cecbf5e43de2e6ba77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037129" comment="alice-compat less than 0.21-207"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037130" comment="autoyast2 less than 2.6.44-27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037131" comment="mkisofs less than 1.11.a28-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037132" comment="perl-XML-DOM less than 1.39-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037133" comment="perl-XML-Generator less than 0.91-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037134" comment="perl-XML-RegExp less than 0.03-422"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037135" comment="syslinux less than 1.62-531"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037136" comment="xntp-doc less than 4.1.1-331"/>
		</criteria>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030501" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0501</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux School Server for i386</platform>
	</affected>
	<reference ref_id="CVE-2003-0501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0501" source="CVE"/>
	<description>
	The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 3ad2793fe2db46f3d3257e03ba28f0fa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037049" comment="kernel-source less than 2.4.19.SuSE-136"/>
	</criteria>
	<!-- 997330ecdb579e177c8d60eb45fcf42c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037051" comment="kernel-ppc64 less than 2.4.19-223"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
	<!-- d3d9eb157fcbc2cecbf5e43de2e6ba77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037129" comment="alice-compat less than 0.21-207"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037130" comment="autoyast2 less than 2.6.44-27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037131" comment="mkisofs less than 1.11.a28-84"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037132" comment="perl-XML-DOM less than 1.39-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037133" comment="perl-XML-Generator less than 0.91-172"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037134" comment="perl-XML-RegExp less than 0.03-422"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037135" comment="syslinux less than 1.62-531"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037136" comment="xntp-doc less than 4.1.1-331"/>
		</criteria>
	</criteria>
	<!-- d510065a7ce35107054d235967897480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037055" comment="kernel-iseries64 less than 2.4.19-233"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030508" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0508</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0508" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0508" source="CVE"/>
	<description>
	Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 146983c4e3b561389880a7d699efcaf6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037142" comment="acroread less than 5.07-2"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037143" comment="acroread less than 5.07-3"/>
		</criteria></criteria>
	<!-- 5d02747ba8a361c887803d92a8e914c3 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037144" comment="acroread less than 5.08-50"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037144" comment="acroread less than 5.08-50"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030542" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0542</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
	</description>
 </metadata>
<!-- b0ad3afc1961097e6bb58010b7dba2c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036808" comment="apache-devel less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036809" comment="apache-devel less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036810" comment="apache-devel less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036812" comment="apache less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036813" comment="apache less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036814" comment="apache less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036816" comment="mod_ssl less than 2.8.3-74"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036817" comment="mod_ssl less than 2.8.3-75"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036818" comment="mod_ssl less than 2.8.4-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036820" comment="apache-devel less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036821" comment="apache less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036822" comment="mod_ssl less than 2.8.10-157"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030543" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0543</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0543" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0543" source="CVE"/>
	<description>
	Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 35ce60f8294623fbb555e94b0bd0e6de -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037145" comment="openssl less than 0.9.6a-83"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037147" comment="openssl less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037148" comment="openssl less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037149" comment="openssl less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
	<!-- 647992725021650687c721cefd2be3db -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037153" comment="openssl-devel less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037154" comment="openssl-devel less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037155" comment="openssl-devel less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030544" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0544</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0544" source="CVE"/>
	<description>
	OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 35ce60f8294623fbb555e94b0bd0e6de -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037145" comment="openssl less than 0.9.6a-83"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037147" comment="openssl less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037148" comment="openssl less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037149" comment="openssl less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
	<!-- 647992725021650687c721cefd2be3db -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037153" comment="openssl-devel less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037154" comment="openssl-devel less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037155" comment="openssl-devel less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030545" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0545</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0545" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0545" source="CVE"/>
	<description>
	Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 35ce60f8294623fbb555e94b0bd0e6de -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037145" comment="openssl less than 0.9.6a-83"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037147" comment="openssl less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037148" comment="openssl less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037149" comment="openssl less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037146" comment="openssl less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037150" comment="openssl less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037151" comment="openssl less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
	<!-- 647992725021650687c721cefd2be3db -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037153" comment="openssl-devel less than 0.9.6g-52"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037154" comment="openssl-devel less than 0.9.6g-53"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037155" comment="openssl-devel less than 0.9.6g-65"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037152" comment="openssl-devel less than 0.9.6g-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037156" comment="openssl-devel less than 0.9.6g-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037157" comment="openssl-devel less than 0.9.6g-99"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0547</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0547" source="CVE"/>
	<description>
	GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.
	</description>
 </metadata>
<!-- 3aa6844b8b167793ea311c09bf8d62f0 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037158" comment="gdm2 less than 2.4.0.11-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037162" comment="gdm2 less than 2.4.0.11-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037163" comment="gdm2 less than 2.4.0.11-55"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037164" comment="gdm2 less than 2.4.1.3-131"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030548" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0548</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0548" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0548" source="CVE"/>
	<description>
	The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
	</description>
 </metadata>
<!-- 3aa6844b8b167793ea311c09bf8d62f0 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037158" comment="gdm2 less than 2.4.0.11-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037162" comment="gdm2 less than 2.4.0.11-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037163" comment="gdm2 less than 2.4.0.11-55"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037164" comment="gdm2 less than 2.4.1.3-131"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030549" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0549</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0549" source="CVE"/>
	<description>
	The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
	</description>
 </metadata>
<!-- 3aa6844b8b167793ea311c09bf8d62f0 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037158" comment="gdm2 less than 2.4.0.11-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037162" comment="gdm2 less than 2.4.0.11-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037163" comment="gdm2 less than 2.4.0.11-55"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037164" comment="gdm2 less than 2.4.1.3-131"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037159" comment="gdm2 less than 2.4.0.11-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037160" comment="gdm2 less than 2.4.0.11-191"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037161" comment="gdm2 less than 2.4.0.11-226"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030619" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0619</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0619" source="CVE"/>
	<description>
	Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 24a68d0a1826e2055e9bd81b5f4d700b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037165" comment="k_deflt less than 2.4.19-256"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037166" comment="k_numa less than 2.4.19-256"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037167" comment="k_smp less than 2.4.19-256"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037168" comment="kernel-source less than 2.4.19.SuSE-256"/>
		</criteria>
	</criteria>
	<!-- 25e414245a6e2511e1e6f6f266f0c2db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037048" comment="kernel-source less than 2.4.19.SuSE-142"/>
	</criteria>
	<!-- 9c5b9c0511fb7890800a4f9081cc7fac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037052" comment="kernel-ppc64 less than 2.4.19-231"/>
	</criteria>
	<!-- c984e74c9e565e9fb7eee625eaae0ce5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037054" comment="kernel-iseries64 less than 2.4.19-239"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030620" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0620</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0620" source="CVE"/>
	<description>
	Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.
	</description>
 </metadata>
<!-- 81b701c55e5bc04d766230fc1e079cc7 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037169" comment="man less than 2.3.17deb3.2-74"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037170" comment="man less than 2.3.19deb4.0-162"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037171" comment="man less than 2.3.19deb4.0-272"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037172" comment="man less than 2.3.19deb4.0-404"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037173" comment="man less than 2.3.19deb4.0-426"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037174" comment="man less than 2.3.19deb4.0-590"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037175" comment="man less than 2.3.19deb4.0-617"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037176" comment="man less than 2.3.19deb4.0-618"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037175" comment="man less than 2.3.19deb4.0-617"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037173" comment="man less than 2.3.19deb4.0-426"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037174" comment="man less than 2.3.19deb4.0-590"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037175" comment="man less than 2.3.19deb4.0-617"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030645" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0645</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0645" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0645" source="CVE"/>
	<description>
	man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.
	</description>
 </metadata>
<!-- 73ea558f54add0d7ac5d745bb1fb86c6 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037177" comment="man less than 2.3.19deb4.0-175"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037178" comment="man less than 2.3.19deb4.0-287"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037179" comment="man less than 2.3.19deb4.0-418"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037180" comment="man less than 2.3.19deb4.0-443"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037181" comment="man less than 2.3.19deb4.0-605"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037182" comment="man less than 2.3.19deb4.0-644"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037182" comment="man less than 2.3.19deb4.0-644"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037180" comment="man less than 2.3.19deb4.0-443"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037181" comment="man less than 2.3.19deb4.0-605"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037182" comment="man less than 2.3.19deb4.0-644"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030682" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0682</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0682" source="CVE"/>
	<description>
	"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
	</description>
 </metadata>
<!-- c96e9e3f3a124a18ba49c393308ad911 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037183" comment="openssh less than 3.4p1-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037184" comment="openssh less than 3.4p1-118"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037188" comment="openssh less than 3.4p1-97"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030686" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0686</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0686" source="CVE"/>
	<description>
	Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- c283b3b890e1a59e4ed8aadc40677785 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037189" comment="pam_smb less than 1.1.6-147"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037190" comment="pam_smb less than 1.1.6-207"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037191" comment="pam_smb less than 1.1.6-240"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037192" comment="pam_smb less than 1.1.6-328"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037193" comment="pam_smb less than 1.1.6-393"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037194" comment="pam_smb less than 1.1.6-500"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037194" comment="pam_smb less than 1.1.6-500"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037190" comment="pam_smb less than 1.1.6-207"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037193" comment="pam_smb less than 1.1.6-393"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037194" comment="pam_smb less than 1.1.6-500"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030688" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0688</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0688" source="CVE"/>
	<description>
	The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
	</description>
 </metadata>
<!-- 846d94f3946701eaa47cdd3c88ae41ce -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037195" comment="sendmail less than 8.12.6-147"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037196" comment="sendmail less than 8.12.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037197" comment="sendmail less than 8.12.6-57"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037198" comment="sendmail less than 8.12.6-58"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037199" comment="sendmail less than 8.12.6-73"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037200" comment="sendmail less than 8.12.6-93"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037195" comment="sendmail less than 8.12.6-147"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037195" comment="sendmail less than 8.12.6-147"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037196" comment="sendmail less than 8.12.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037200" comment="sendmail less than 8.12.6-93"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030690" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0690</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0690" source="CVE"/>
	<description>
	KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ce03328e99cd55bf51cef47bc89f29f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037201" comment="kdebase3-devel less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037202" comment="kdebase3-devel less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037203" comment="kdebase3-devel less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037204" comment="kdebase3-devel less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037205" comment="kdebase3-devel less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037206" comment="kdebase3-devel less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037207" comment="kdebase3-kdm less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037208" comment="kdebase3-kdm less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037209" comment="kdebase3-kdm less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037210" comment="kdebase3-kdm less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037211" comment="kdebase3-kdm less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037212" comment="kdebase3-kdm less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037213" comment="kdebase3-konqueror less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037214" comment="kdebase3-konqueror less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037215" comment="kdebase3-konqueror less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037216" comment="kdebase3-konqueror less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037217" comment="kdebase3-konqueror less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037218" comment="kdebase3-konqueror less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037219" comment="kdebase3-ksysguardd less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037220" comment="kdebase3-ksysguardd less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037221" comment="kdebase3-ksysguardd less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037222" comment="kdebase3-ksysguardd less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037223" comment="kdebase3-ksysguardd less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037224" comment="kdebase3-ksysguardd less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037225" comment="kdebase3-nsplugin less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037226" comment="kdebase3-nsplugin less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037227" comment="kdebase3-nsplugin less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037228" comment="kdebase3-nsplugin less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037229" comment="kdebase3-nsplugin less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037230" comment="kdebase3-nsplugin less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037231" comment="kdebase3 less than 3.0.3-111"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037232" comment="kdebase3 less than 3.0.3-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037233" comment="kdebase3 less than 3.0.3-137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037234" comment="kdebase3 less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037235" comment="kdebase3 less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037236" comment="kdebase3 less than 3.0.3-232"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037206" comment="kdebase3-devel less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037212" comment="kdebase3-kdm less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037218" comment="kdebase3-konqueror less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037224" comment="kdebase3-ksysguardd less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037230" comment="kdebase3-nsplugin less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037236" comment="kdebase3 less than 3.0.3-232"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037204" comment="kdebase3-devel less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037205" comment="kdebase3-devel less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037206" comment="kdebase3-devel less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037210" comment="kdebase3-kdm less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037211" comment="kdebase3-kdm less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037212" comment="kdebase3-kdm less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037216" comment="kdebase3-konqueror less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037217" comment="kdebase3-konqueror less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037218" comment="kdebase3-konqueror less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037222" comment="kdebase3-ksysguardd less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037223" comment="kdebase3-ksysguardd less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037224" comment="kdebase3-ksysguardd less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037228" comment="kdebase3-nsplugin less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037229" comment="kdebase3-nsplugin less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037230" comment="kdebase3-nsplugin less than 3.0.3-232"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037234" comment="kdebase3 less than 3.0.3-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037235" comment="kdebase3 less than 3.0.3-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037236" comment="kdebase3 less than 3.0.3-232"/>
			</criteria>
		</criteria></criteria>
	<!-- 85ed761974b70af5fdd4f88d156fd486 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037237" comment="kdebase3-kdm less than 3.0.3-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037238" comment="kdebase3-kdm less than 3.0.3-113"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037239" comment="kdebase3-kdm less than 3.0.3-133"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037240" comment="kdebase3-kdm less than 3.0.3-139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037241" comment="kdebase3-kdm less than 3.0.3-204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037242" comment="kdebase3-kdm less than 3.0.3-228"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037243" comment="kdebase3-kdm less than 3.1.1-134"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037242" comment="kdebase3-kdm less than 3.0.3-228"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037240" comment="kdebase3-kdm less than 3.0.3-139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037241" comment="kdebase3-kdm less than 3.0.3-204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037242" comment="kdebase3-kdm less than 3.0.3-228"/>
			</criteria>
		</criteria></criteria>
	<!-- 88289d1e85f1ee6ac1a1ce84ea475481 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037244" comment="XFree86 less than 4.3.0-115"/>
	</criteria>
	<!-- b4b5d382e65efa78bae8495095d801bb -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037245" comment="xf86 less than 4.2.0-104"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037246" comment="xf86 less than 4.2.0-113"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037247" comment="xf86 less than 4.2.0-161"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037248" comment="xf86 less than 4.2.0-174"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037249" comment="xf86 less than 4.2.0-186"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037250" comment="xf86 less than 4.2.0-249"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037250" comment="xf86 less than 4.2.0-249"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037247" comment="xf86 less than 4.2.0-161"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037249" comment="xf86 less than 4.2.0-186"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037250" comment="xf86 less than 4.2.0-249"/>
			</criteria>
		</criteria></criteria>
	<!-- eff331987ff70497806f83e5dcd22d47 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037243" comment="kdebase3-kdm less than 3.1.1-134"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030693" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0693</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693" source="CVE"/>
	<description>
	A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a1b94c8b5da0188997516c960ed592d1 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037251" comment="openssh less than 3.4p1-101"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037252" comment="openssh less than 3.4p1-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037253" comment="openssh less than 3.4p1-139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037254" comment="openssh less than 3.4p1-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037255" comment="openssh less than 3.4p1-214"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037256" comment="openssh less than 3.4p1-96"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037255" comment="openssh less than 3.4p1-214"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037253" comment="openssh less than 3.4p1-139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037254" comment="openssh less than 3.4p1-208"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037255" comment="openssh less than 3.4p1-214"/>
			</criteria>
		</criteria></criteria>
	<!-- c96e9e3f3a124a18ba49c393308ad911 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037183" comment="openssh less than 3.4p1-102"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037184" comment="openssh less than 3.4p1-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037188" comment="openssh less than 3.4p1-97"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030694" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0694</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694" source="CVE"/>
	<description>
	The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
	</description>
 </metadata>
<!-- f8b97eb6f8defd39d638f570b103a516 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037257" comment="sendmail less than 8.11.3-112"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037258" comment="sendmail less than 8.12.6-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037259" comment="sendmail less than 8.12.6-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037260" comment="sendmail less than 8.12.6-159"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037261" comment="sendmail less than 8.12.6-62"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037262" comment="sendmail less than 8.12.6-64"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037263" comment="sendmail less than 8.12.6-79"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037260" comment="sendmail less than 8.12.6-159"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037258" comment="sendmail less than 8.12.6-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037259" comment="sendmail less than 8.12.6-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037260" comment="sendmail less than 8.12.6-159"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030695" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0695</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0695" source="CVE"/>
	<description>
	Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.
	</description>
 </metadata>
<!-- c96e9e3f3a124a18ba49c393308ad911 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037183" comment="openssh less than 3.4p1-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037184" comment="openssh less than 3.4p1-118"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037188" comment="openssh less than 3.4p1-97"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037185" comment="openssh less than 3.4p1-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037186" comment="openssh less than 3.4p1-209"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037187" comment="openssh less than 3.4p1-215"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030709" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0709</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0709" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0709" source="CVE"/>
	<description>
	Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
	</description>
 </metadata>
<!-- 6c4d7fa9f6686e68f51e38caf8a9022f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037264" comment="whois less than 4.5.29-116"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037265" comment="whois less than 4.5.29-48"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037266" comment="whois less than 4.5.29-53"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037267" comment="whois less than 4.5.29-58"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037268" comment="whois less than 4.5.29-66"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037269" comment="whois less than 4.5.29-94"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037269" comment="whois less than 4.5.29-94"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037264" comment="whois less than 4.5.29-116"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037268" comment="whois less than 4.5.29-66"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037269" comment="whois less than 4.5.29-94"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030720" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0720</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0720" source="CVE"/>
	<description>
	Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
	</description>
 </metadata>
<!-- ea6c1fcab2310daef25b46039b4b3d02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037270" comment="pico less than 4.44-282"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037271" comment="pine less than 4.44-282"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030721" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0721</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0721" source="CVE"/>
	<description>
	Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.
	</description>
 </metadata>
<!-- ea6c1fcab2310daef25b46039b4b3d02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037270" comment="pico less than 4.44-282"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037271" comment="pine less than 4.44-282"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030773" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0773</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0773" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030774" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0774</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0774" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030775" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0775</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0775" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030776" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0776</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0776" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030777" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0777</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0777" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030778" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0778</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0778" source="CVE"/>
	<description>
	saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).
	</description>
 </metadata>
<!-- 037b89db18ce7008d911efba35e6498a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037272" comment="sane less than 1.0.8-141"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030780" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0780</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0780" source="CVE"/>
	<description>
	Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0326ffe7c9586492efd64c562c7ac9d6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037273" comment="mysql-devel less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037274" comment="mysql-devel less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037275" comment="mysql-devel less than 3.23.52-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037276" comment="mysql-devel less than 3.23.52-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037277" comment="mysql-devel less than 3.23.52-66"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037278" comment="mysql-devel less than 3.23.52-73"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037273" comment="mysql-devel less than 3.23.52-106"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037273" comment="mysql-devel less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037274" comment="mysql-devel less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037278" comment="mysql-devel less than 3.23.52-73"/>
			</criteria>
		</criteria></criteria>
	<!-- 105100443950995a8cecd29f4983ae43 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037096" comment="mod_php4-core less than 4.2.2-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037097" comment="mod_php4-core less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037098" comment="mod_php4-core less than 4.2.2-131"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037100" comment="mod_php4-core less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037101" comment="mod_php4-core less than 4.2.2-84"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037102" comment="mod_php4-devel less than 4.2.2-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037103" comment="mod_php4-devel less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037104" comment="mod_php4-devel less than 4.2.2-131"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037106" comment="mod_php4-devel less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037107" comment="mod_php4-devel less than 4.2.2-84"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037108" comment="mod_php4-servlet less than 4.2.2-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037109" comment="mod_php4-servlet less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037110" comment="mod_php4-servlet less than 4.2.2-131"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037112" comment="mod_php4-servlet less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037113" comment="mod_php4-servlet less than 4.2.2-84"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037114" comment="mod_php4 less than 4.2.2-109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037115" comment="mod_php4 less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037116" comment="mod_php4 less than 4.2.2-131"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037118" comment="mod_php4 less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037119" comment="mod_php4 less than 4.2.2-84"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037097" comment="mod_php4-core less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037099" comment="mod_php4-core less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037100" comment="mod_php4-core less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037103" comment="mod_php4-devel less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037105" comment="mod_php4-devel less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037106" comment="mod_php4-devel less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037109" comment="mod_php4-servlet less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037111" comment="mod_php4-servlet less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037112" comment="mod_php4-servlet less than 4.2.2-359"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037115" comment="mod_php4 less than 4.2.2-121"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037117" comment="mod_php4 less than 4.2.2-255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037118" comment="mod_php4 less than 4.2.2-359"/>
			</criteria>
		</criteria></criteria>
	<!-- 29c35c21785307a81e5df036c99fa60a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037279" comment="mysql-shared less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037280" comment="mysql-shared less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037281" comment="mysql-shared less than 3.23.52-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037282" comment="mysql-shared less than 3.23.52-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037283" comment="mysql-shared less than 3.23.52-66"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037284" comment="mysql-shared less than 3.23.52-73"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037279" comment="mysql-shared less than 3.23.52-106"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037279" comment="mysql-shared less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037280" comment="mysql-shared less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037284" comment="mysql-shared less than 3.23.52-73"/>
			</criteria>
		</criteria></criteria>
	<!-- 4bf379bd73f1b07ad1c4c68e37a5d5da -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037285" comment="mysql-client less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037286" comment="mysql-client less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037287" comment="mysql-client less than 3.23.52-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037288" comment="mysql-client less than 3.23.52-63"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037289" comment="mysql-client less than 3.23.52-66"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037290" comment="mysql-client less than 3.23.52-73"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037285" comment="mysql-client less than 3.23.52-106"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037285" comment="mysql-client less than 3.23.52-106"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037286" comment="mysql-client less than 3.23.52-107"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037290" comment="mysql-client less than 3.23.52-73"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030788" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0788</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0788" source="CVE"/>
	<description>
	Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).
	</description>
 </metadata>
<!-- 23897040f27d42f010cbf2c55d3bd772 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037291" comment="cups-client less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037292" comment="cups-client less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037293" comment="cups-client less than 1.1.15-80"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037294" comment="cups-client less than 1.1.15-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037295" comment="cups-client less than 1.1.15-90"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037296" comment="cups-client less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037297" comment="cups-devel less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037298" comment="cups-devel less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037299" comment="cups-devel less than 1.1.15-80"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037300" comment="cups-devel less than 1.1.15-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037301" comment="cups-devel less than 1.1.15-90"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037302" comment="cups-devel less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037303" comment="cups-libs less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037304" comment="cups-libs less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037305" comment="cups-libs less than 1.1.15-80"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037306" comment="cups-libs less than 1.1.15-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037307" comment="cups-libs less than 1.1.15-90"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037308" comment="cups-libs less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037309" comment="cups less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037310" comment="cups less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037311" comment="cups less than 1.1.15-80"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037312" comment="cups less than 1.1.15-81"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037313" comment="cups less than 1.1.15-90"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037314" comment="cups less than 1.1.15-91"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037291" comment="cups-client less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037297" comment="cups-devel less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037303" comment="cups-libs less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037309" comment="cups less than 1.1.15-132"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037291" comment="cups-client less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037292" comment="cups-client less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037296" comment="cups-client less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037297" comment="cups-devel less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037298" comment="cups-devel less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037302" comment="cups-devel less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037303" comment="cups-libs less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037304" comment="cups-libs less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037308" comment="cups-libs less than 1.1.15-91"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037309" comment="cups less than 1.1.15-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037310" comment="cups less than 1.1.15-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037314" comment="cups less than 1.1.15-91"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030793" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0793</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0793" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0793" source="CVE"/>
	<description>
	GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9c37d948cceb36cca98e8a693f2be36e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037315" comment="gdm2 less than 2.4.0.11-116"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037316" comment="gdm2 less than 2.4.0.11-145"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037317" comment="gdm2 less than 2.4.0.11-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037319" comment="gdm2 less than 2.4.0.11-59"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037320" comment="gdm2 less than 2.4.0.11-67"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037316" comment="gdm2 less than 2.4.0.11-145"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037317" comment="gdm2 less than 2.4.0.11-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
			</criteria>
		</criteria></criteria>
	<!-- b226e1a1adeaa27514b31168acc54dd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037321" comment="gdm2 less than 2.4.1.3-151"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030794" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0794</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0794" source="CVE"/>
	<description>
	GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9c37d948cceb36cca98e8a693f2be36e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037315" comment="gdm2 less than 2.4.0.11-116"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037316" comment="gdm2 less than 2.4.0.11-145"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037317" comment="gdm2 less than 2.4.0.11-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037319" comment="gdm2 less than 2.4.0.11-59"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037320" comment="gdm2 less than 2.4.0.11-67"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037316" comment="gdm2 less than 2.4.0.11-145"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037317" comment="gdm2 less than 2.4.0.11-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037318" comment="gdm2 less than 2.4.0.11-246"/>
			</criteria>
		</criteria></criteria>
	<!-- b226e1a1adeaa27514b31168acc54dd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037321" comment="gdm2 less than 2.4.1.3-151"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030854" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0854</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0854" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0854" source="CVE"/>
	<description>
	ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.
	</description>
 </metadata>
<!-- 0a4ae2e775aad02a75d07691a83a71d4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037322" comment="fileutils less than 4.0.35-76"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037323" comment="fileutils less than 4.1.11-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037324" comment="fileutils less than 4.1.11-123"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037325" comment="fileutils less than 4.1.11-59"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037326" comment="fileutils less than 4.1.11-60"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037327" comment="fileutils less than 4.1.11-72"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037328" comment="fileutils less than 4.1.11-79"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037323" comment="fileutils less than 4.1.11-107"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037323" comment="fileutils less than 4.1.11-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037324" comment="fileutils less than 4.1.11-123"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037328" comment="fileutils less than 4.1.11-79"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030856" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0856</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0856" source="CVE"/>
	<description>
	iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.
	</description>
 </metadata>
<!-- 9874b4d93537973f551c3a967fce6726 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030405" comment="iproute2 less than 2.4.7-866.8"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037329" comment="iproute2 less than 2.4.7-873"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030858" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0858</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0858" source="CVE"/>
	<description>
	Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 15e12a9211e724ecf2c8212a01477ca3 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037330" comment="zebra less than 0.93b-120"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037331" comment="zebra less than 0.93b-146"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037332" comment="zebra less than 0.93b-149"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037333" comment="zebra less than 0.93b-67"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037334" comment="zebra less than 0.93b-75"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037335" comment="zebra less than 0.93b-88"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037332" comment="zebra less than 0.93b-149"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037330" comment="zebra less than 0.93b-120"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037331" comment="zebra less than 0.93b-146"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037332" comment="zebra less than 0.93b-149"/>
			</criteria>
		</criteria></criteria>
	<!-- 54656f7126dc88db89a8c620d73612cf -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037336" comment="zebra less than 0.93b-129"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037337" comment="zebra less than 0.93b-162"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037338" comment="zebra less than 0.93b-163"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037334" comment="zebra less than 0.93b-75"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037339" comment="zebra less than 0.93b-83"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037340" comment="zebra less than 0.93b-95"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037338" comment="zebra less than 0.93b-163"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037336" comment="zebra less than 0.93b-129"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037337" comment="zebra less than 0.93b-162"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037338" comment="zebra less than 0.93b-163"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030864" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0864</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0864" source="CVE"/>
	<description>
	Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.
	</description>
 </metadata>
<!-- 156ff95300e28698cbfa6c5c6bb9b0fd -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037341" comment="ircd less than 2.10.3-118"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037342" comment="ircd less than 2.10.3-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037343" comment="ircd less than 2.10.3-253"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037344" comment="ircd less than 2.10.3-339"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037345" comment="ircd less than 2.10.3-375"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037346" comment="ircd less than 2.10.3-483"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037346" comment="ircd less than 2.10.3-483"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037342" comment="ircd less than 2.10.3-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037345" comment="ircd less than 2.10.3-375"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037346" comment="ircd less than 2.10.3-483"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030886" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0886</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2003-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0886" source="CVE"/>
	<description>
	Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- fa498c2ffd43163d6d4c8b1442a02162 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037347" comment="hylafax less than 4.1.5-185"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037348" comment="hylafax less than 4.1.3-143"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030901" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0901</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0901" source="CVE"/>
	<description>
	Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 25e2ac7f5d87c4e11b40fd9e6fb5e372 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037349" comment="postgresql-server less than 7.2.2-134"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037350" comment="postgresql-server less than 7.2.2-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037351" comment="postgresql-server less than 7.2.2-60"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037352" comment="postgresql-server less than 7.2.2-62"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037353" comment="postgresql-server less than 7.2.2-69"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037354" comment="postgresql-server less than 7.2.2-86"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037349" comment="postgresql-server less than 7.2.2-134"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037349" comment="postgresql-server less than 7.2.2-134"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037350" comment="postgresql-server less than 7.2.2-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037354" comment="postgresql-server less than 7.2.2-86"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030924" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0924</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 900c8b74c9124d1d40f9a54aa303645a -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037355" comment="netpbm less than 10.5-122"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037356" comment="netpbm less than 10.5-136"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037357" comment="netpbm less than 10.5-76"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037358" comment="netpbm less than 10.5-77"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037359" comment="netpbm less than 10.5-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037360" comment="netpbm less than 10.5-90"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037355" comment="netpbm less than 10.5-122"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030925" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0925</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0925" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0925" source="CVE"/>
	<description>
	Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.
	</description>
 </metadata>
<!-- 62e23650071849bb994c2c9d620e8839 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036854" comment="ethereal less than 0.9.6-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037361" comment="ethereal less than 0.9.6-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037362" comment="ethereal less than 0.9.6-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030926" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0926</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0926" source="CVE"/>
	<description>
	Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.
	</description>
 </metadata>
<!-- 62e23650071849bb994c2c9d620e8839 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036854" comment="ethereal less than 0.9.6-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037361" comment="ethereal less than 0.9.6-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037362" comment="ethereal less than 0.9.6-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030927" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0927</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0927" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0927" source="CVE"/>
	<description>
	Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.
	</description>
 </metadata>
<!-- 62e23650071849bb994c2c9d620e8839 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036854" comment="ethereal less than 0.9.6-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037361" comment="ethereal less than 0.9.6-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037362" comment="ethereal less than 0.9.6-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037363" comment="ethereal less than 0.9.6-148"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037364" comment="ethereal less than 0.9.6-206"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037365" comment="ethereal less than 0.9.6-246"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030961" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0961</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961" source="CVE"/>
	<description>
	Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d3b8661b6091d029efff7bd34c76ce8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036803" comment="k_psmp less than 2.4.19-346"/>
	</criteria>
	<!-- a91d13d9b8aa9ba852f3fd48b5a47993 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036804" comment="k_smp less than 2.4.19-346"/>
	</criteria>
	<!-- d69260901a5db56058a50e1a21e88429 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036805" comment="kernel-source less than 2.4.19.SuSE-346"/>
	</criteria>
	<!-- d8b8e10e2caef5026bf709bf4cd6672f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036806" comment="k_deflt less than 2.4.19-346"/>
	</criteria>
	<!-- debc85a657ac36c9b4b05c32fd479477 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036807" comment="k_athlon less than 2.4.19-346"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030962" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0962</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0962" source="CVE"/>
	<description>
	Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
	</description>
 </metadata>
<!-- bb1de7b45a0b6e585f76ea3128a45b7e -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037366" comment="rsync less than 2.5.5-103"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037367" comment="rsync less than 2.5.5-116"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037368" comment="rsync less than 2.5.5-127"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037369" comment="rsync less than 2.5.5-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037370" comment="rsync less than 2.5.5-233"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037371" comment="rsync less than 2.5.5-258"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037371" comment="rsync less than 2.5.5-258"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037369" comment="rsync less than 2.5.5-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037370" comment="rsync less than 2.5.5-233"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037371" comment="rsync less than 2.5.5-258"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030967" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0967</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0967" source="CVE"/>
	<description>
	rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.
	</description>
 </metadata>
<!-- f0f04ff8205d9544fec5283cfca961af -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037372" comment="freeradius-devel less than 0.5-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037373" comment="freeradius-devel less than 0.5-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037374" comment="freeradius-devel less than 0.5-193"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037375" comment="freeradius-devel less than 0.5-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037376" comment="freeradius-devel less than 0.5-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037377" comment="freeradius-devel less than 0.5-377"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037378" comment="freeradius less than 0.5-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037379" comment="freeradius less than 0.5-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037380" comment="freeradius less than 0.5-193"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037381" comment="freeradius less than 0.5-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037382" comment="freeradius less than 0.5-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037383" comment="freeradius less than 0.5-377"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037377" comment="freeradius-devel less than 0.5-377"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037383" comment="freeradius less than 0.5-377"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037375" comment="freeradius-devel less than 0.5-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037376" comment="freeradius-devel less than 0.5-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037377" comment="freeradius-devel less than 0.5-377"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037381" comment="freeradius less than 0.5-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037382" comment="freeradius less than 0.5-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037383" comment="freeradius less than 0.5-377"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030971" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0971</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0971" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0971" source="CVE"/>
	<description>
	GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
	</description>
 </metadata>
<!-- 1e68d2df30cb7c2363583ce10e998207 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037384" comment="gpg less than 1.2.2rc1-98"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030972" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0972</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0972" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0972" source="CVE"/>
	<description>
	Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
	</description>
 </metadata>
<!-- e47cfb21ff6d7c698aed78e2d47bd32d -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037385" comment="screen less than 3.9.13-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037386" comment="screen less than 3.9.13-147"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037387" comment="screen less than 3.9.13-167"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037388" comment="screen less than 3.9.13-64"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037389" comment="screen less than 3.9.13-69"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037390" comment="screen less than 3.9.13-79"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037386" comment="screen less than 3.9.13-147"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037385" comment="screen less than 3.9.13-105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037386" comment="screen less than 3.9.13-147"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037387" comment="screen less than 3.9.13-167"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030977" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0977</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977" source="CVE"/>
	<description>
	CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.
	</description>
 </metadata>
<!-- b1c122d333ae4a483000536d145c4580 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037391" comment="cvs less than 1.11.1p1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037392" comment="cvs less than 1.11.1p1-124"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037393" comment="cvs less than 1.11.1p1-181"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037394" comment="cvs less than 1.11.1p1-198"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037395" comment="cvs less than 1.11.1p1-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037396" comment="cvs less than 1.11.1p1-306"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037396" comment="cvs less than 1.11.1p1-306"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037393" comment="cvs less than 1.11.1p1-181"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037395" comment="cvs less than 1.11.1p1-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037396" comment="cvs less than 1.11.1p1-306"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030978" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0978</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0978" source="CVE"/>
	<description>
	Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.
	</description>
 </metadata>
<!-- 1e68d2df30cb7c2363583ce10e998207 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037384" comment="gpg less than 1.2.2rc1-98"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030985" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0985</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e77cff4ad0d77841d2124a2854245e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037397" comment="kernel-iseries64 less than 2.4.21-130"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037398" comment="kernel-ppc64 less than 2.4.21-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037399" comment="kernel-source less than 2.4.21-128"/>
		</criteria>
	</criteria>
	<!-- 513d19fdca08209fd14957910bfa46e9 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037400" comment="k_athlon less than 2.4.21-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037401" comment="k_deflt less than 2.4.21-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037402" comment="k_psmp less than 2.4.21-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037403" comment="k_smp less than 2.4.21-169"/>
		</criteria>
	</criteria>
	<!-- beaed2f4513e03b76e02a72a130986a3 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037404" comment="k_debug less than 2.4.21-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037405" comment="kernel-source less than 2.4.21-177"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030987" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0987</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987" source="CVE"/>
	<description>
	mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
	</description>
 </metadata>
<!-- b0ad3afc1961097e6bb58010b7dba2c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036808" comment="apache-devel less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036809" comment="apache-devel less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036810" comment="apache-devel less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036812" comment="apache less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036813" comment="apache less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036814" comment="apache less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036816" comment="mod_ssl less than 2.8.3-74"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036817" comment="mod_ssl less than 2.8.3-75"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036818" comment="mod_ssl less than 2.8.4-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036820" comment="apache-devel less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036821" comment="apache less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036822" comment="mod_ssl less than 2.8.10-157"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030988" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0988</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 13a79735a56c92c0f313a3af37119d61 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037406" comment="kdepim3 less than 3.1.1-161"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030989" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0989</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989" source="CVE"/>
	<description>
	tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
	</description>
 </metadata>
<!-- 04508bb56d50b24bd45f8fd8e9b81179 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037407" comment="tcpdump less than 3.4a6-389"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037408" comment="tcpdump less than 3.7.1-128"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037409" comment="tcpdump less than 3.7.1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037410" comment="tcpdump less than 3.7.1-176"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037411" comment="tcpdump less than 3.7.1-223"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037412" comment="tcpdump less than 3.7.1-341"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037412" comment="tcpdump less than 3.7.1-341"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037411" comment="tcpdump less than 3.7.1-223"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037412" comment="tcpdump less than 3.7.1-341"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030991" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0991</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0991" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0991" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 72a78c5c8d7e55cd868624ff1c986d72 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037413" comment="mailman less than 2.0.14-12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037414" comment="mailman less than 2.0.14-18"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037415" comment="mailman less than 2.0.14-5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037416" comment="mailman less than 2.0.14-6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037414" comment="mailman less than 2.0.14-18"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037413" comment="mailman less than 2.0.14-12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037414" comment="mailman less than 2.0.14-18"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037416" comment="mailman less than 2.0.14-6"/>
			</criteria>
		</criteria></criteria>
	<!-- be0d5ccc5b9e4d3436c559203cc25293 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037414" comment="mailman less than 2.0.14-18"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030993" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-0993</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-0993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- b0ad3afc1961097e6bb58010b7dba2c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036808" comment="apache-devel less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036809" comment="apache-devel less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036810" comment="apache-devel less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036812" comment="apache less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036813" comment="apache less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036814" comment="apache less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036816" comment="mod_ssl less than 2.8.3-74"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036817" comment="mod_ssl less than 2.8.3-75"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036818" comment="mod_ssl less than 2.8.4-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036820" comment="apache-devel less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036821" comment="apache less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036822" comment="mod_ssl less than 2.8.10-157"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031012" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1012</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012" source="CVE"/>
	<description>
	The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.
	</description>
 </metadata>
<!-- 0acbeb0462fad0d53fb9bbc053aacdb2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037417" comment="ethereal less than 0.9.6-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037418" comment="ethereal less than 0.9.6-110"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037419" comment="ethereal less than 0.9.6-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037420" comment="ethereal less than 0.9.6-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037421" comment="ethereal less than 0.9.6-214"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037420" comment="ethereal less than 0.9.6-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037421" comment="ethereal less than 0.9.6-214"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031013" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1013</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013" source="CVE"/>
	<description>
	The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.
	</description>
 </metadata>
<!-- 0acbeb0462fad0d53fb9bbc053aacdb2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037417" comment="ethereal less than 0.9.6-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037418" comment="ethereal less than 0.9.6-110"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037419" comment="ethereal less than 0.9.6-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037420" comment="ethereal less than 0.9.6-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037421" comment="ethereal less than 0.9.6-214"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037420" comment="ethereal less than 0.9.6-156"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037421" comment="ethereal less than 0.9.6-214"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037422" comment="ethereal less than 0.9.6-260"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031023" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1023</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023" source="CVE"/>
	<description>
	Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.
	</description>
 </metadata>
<!-- 86209fd5040d8db0d179111173b54dad -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037423" comment="mc less than 4.5.51-171"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037424" comment="mc less than 4.5.55-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037425" comment="mc less than 4.5.55-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037426" comment="mc less than 4.5.55-365"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037427" comment="mc less than 4.5.55-379"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037428" comment="mc less than 4.5.55-386"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037429" comment="mc less than 4.5.55-719"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037430" comment="mc less than 4.5.55-717"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037429" comment="mc less than 4.5.55-719"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037427" comment="mc less than 4.5.55-379"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037428" comment="mc less than 4.5.55-386"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037429" comment="mc less than 4.5.55-719"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031029" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1029</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1029" source="CVE"/>
	<description>
	The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.
	</description>
 </metadata>
<!-- 27149b8f7feae5e2b22e02851f0a3af3 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037431" comment="tcpdump less than 3.7.1-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037432" comment="tcpdump less than 3.7.1-168"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037433" comment="tcpdump less than 3.7.1-180"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037437" comment="tcpdump less than 3.7.1-350"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031232" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1232</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1232" source="CVE"/>
	<description>
	Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
	</description>
 </metadata>
<!-- d5a3b8a08021cad595eccfd4646079c2 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037438" comment="emacs less than 21.2-268"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1302</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1302" source="CVE"/>
	<description>
	The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.
	</description>
 </metadata>
<!-- d9cee2b4664d18e6170131684c7b9c0c -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036795" comment="mod_php4-core less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036796" comment="mod_php4-devel less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036797" comment="mod_php4-servlet less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036798" comment="mod_php4 less than 4.2.2-510"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031303" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1303</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2003-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1303" source="CVE"/>
	<description>
	Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.
	</description>
 </metadata>
<!-- d9cee2b4664d18e6170131684c7b9c0c -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036795" comment="mod_php4-core less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036796" comment="mod_php4-devel less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036797" comment="mod_php4-servlet less than 4.2.2-510"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036798" comment="mod_php4 less than 4.2.2-510"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031538" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2003-1538</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
	</affected>
	<reference ref_id="CVE-2003-1538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1538" source="CVE"/>
	<description>
	susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.
	</description>
 </metadata>
<!-- 1ef8f79eba961050c42817af8b17aa23 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037439" comment="susehelp less than 2002.09.05-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037440" comment="susehelp less than 2002.09.05-35"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037441" comment="susehelp less than 2002.09.05-51"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037441" comment="susehelp less than 2002.09.05-51"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040003" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0003</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003" source="CVE"/>
	<description>
	Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1edbffa2bbcd8c75a2d0e2d2ad287d33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037442" comment="kernel-iseries64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037443" comment="kernel-ppc64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037444" comment="kernel-source less than 2.4.21-146"/>
		</criteria>
	</criteria>
	<!-- 2f9b360b813a46151bbe467a34f53b2a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037445" comment="k_athlon less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037446" comment="k_deflt less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037447" comment="k_psmp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037448" comment="k_smp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037449" comment="kernel-source less than 2.4.19.SuSE-349"/>
		</criteria>
	</criteria>
	<!-- 53bc5acb21c04e186b64731967c3f1fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037450" comment="k_athlon less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037451" comment="k_debug less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037452" comment="k_deflt less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037453" comment="k_psmp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037454" comment="k_smp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037455" comment="kernel-source less than 2.4.21-190"/>
		</criteria>
	</criteria>
	<!-- 81063858996de55347cb1163516a80cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037456" comment="k_deflt less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037457" comment="k_numa less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037458" comment="k_smp less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037459" comment="kernel-source less than 2.4.21-199"/>
		</criteria>
	</criteria>
	<!-- 9a0ec51236057e43d4176965cdd39ff0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037460" comment="k_deflt less than 2.4.21-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037461" comment="kernel-source less than 2.4.21-107"/>
		</criteria>
	</criteria>
	<!-- b0f1248576f4ba7a88b35a839945b272 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037462" comment="k_deflt less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037463" comment="k_itanium2-smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037464" comment="k_itanium2 less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037465" comment="k_smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037466" comment="kernel-source less than 2.4.21-144"/>
		</criteria>
	</criteria>
	<!-- e99e0bf873ed99011fadda29134213da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037467" comment="k_deflt less than 2.4.21-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037468" comment="kernel-source less than 2.4.21-102"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040005" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0005</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0005" source="CVE"/>
	<description>
	Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.
	</description>
 </metadata>
<!-- 656e02d4c40a791f273cba0eb64e33a3 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037469" comment="gaim less than 0.59-158"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040006" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0006</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006" source="CVE"/>
	<description>
	Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.
	</description>
 </metadata>
<!-- 656e02d4c40a791f273cba0eb64e33a3 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037469" comment="gaim less than 0.59-158"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040007" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0007</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007" source="CVE"/>
	<description>
	Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
	</description>
 </metadata>
<!-- 656e02d4c40a791f273cba0eb64e33a3 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037469" comment="gaim less than 0.59-158"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040010" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0010</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010" source="CVE"/>
	<description>
	Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1edbffa2bbcd8c75a2d0e2d2ad287d33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037442" comment="kernel-iseries64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037443" comment="kernel-ppc64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037444" comment="kernel-source less than 2.4.21-146"/>
		</criteria>
	</criteria>
	<!-- 2f9b360b813a46151bbe467a34f53b2a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037445" comment="k_athlon less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037446" comment="k_deflt less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037447" comment="k_psmp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037448" comment="k_smp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037449" comment="kernel-source less than 2.4.19.SuSE-349"/>
		</criteria>
	</criteria>
	<!-- 53bc5acb21c04e186b64731967c3f1fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037450" comment="k_athlon less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037451" comment="k_debug less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037452" comment="k_deflt less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037453" comment="k_psmp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037454" comment="k_smp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037455" comment="kernel-source less than 2.4.21-190"/>
		</criteria>
	</criteria>
	<!-- 81063858996de55347cb1163516a80cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037456" comment="k_deflt less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037457" comment="k_numa less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037458" comment="k_smp less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037459" comment="kernel-source less than 2.4.21-199"/>
		</criteria>
	</criteria>
	<!-- 9a0ec51236057e43d4176965cdd39ff0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037460" comment="k_deflt less than 2.4.21-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037461" comment="kernel-source less than 2.4.21-107"/>
		</criteria>
	</criteria>
	<!-- b0f1248576f4ba7a88b35a839945b272 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037462" comment="k_deflt less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037463" comment="k_itanium2-smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037464" comment="k_itanium2 less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037465" comment="k_smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037466" comment="kernel-source less than 2.4.21-144"/>
		</criteria>
	</criteria>
	<!-- e99e0bf873ed99011fadda29134213da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037467" comment="k_deflt less than 2.4.21-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037468" comment="kernel-source less than 2.4.21-102"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040055" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0055</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055" source="CVE"/>
	<description>
	The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.
	</description>
 </metadata>
<!-- 27149b8f7feae5e2b22e02851f0a3af3 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037431" comment="tcpdump less than 3.7.1-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037432" comment="tcpdump less than 3.7.1-168"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037433" comment="tcpdump less than 3.7.1-180"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037437" comment="tcpdump less than 3.7.1-350"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040057" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0057</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057" source="CVE"/>
	<description>
	The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.
	</description>
 </metadata>
<!-- 27149b8f7feae5e2b22e02851f0a3af3 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037431" comment="tcpdump less than 3.7.1-132"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037432" comment="tcpdump less than 3.7.1-168"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037433" comment="tcpdump less than 3.7.1-180"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037437" comment="tcpdump less than 3.7.1-350"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037434" comment="tcpdump less than 3.7.1-229"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037435" comment="tcpdump less than 3.7.1-342"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037436" comment="tcpdump less than 3.7.1-351"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040075" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0075</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1edbffa2bbcd8c75a2d0e2d2ad287d33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037442" comment="kernel-iseries64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037443" comment="kernel-ppc64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037444" comment="kernel-source less than 2.4.21-146"/>
		</criteria>
	</criteria>
	<!-- 2f9b360b813a46151bbe467a34f53b2a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037445" comment="k_athlon less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037446" comment="k_deflt less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037447" comment="k_psmp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037448" comment="k_smp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037449" comment="kernel-source less than 2.4.19.SuSE-349"/>
		</criteria>
	</criteria>
	<!-- 53bc5acb21c04e186b64731967c3f1fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037450" comment="k_athlon less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037451" comment="k_debug less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037452" comment="k_deflt less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037453" comment="k_psmp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037454" comment="k_smp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037455" comment="kernel-source less than 2.4.21-190"/>
		</criteria>
	</criteria>
	<!-- 81063858996de55347cb1163516a80cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037456" comment="k_deflt less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037457" comment="k_numa less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037458" comment="k_smp less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037459" comment="kernel-source less than 2.4.21-199"/>
		</criteria>
	</criteria>
	<!-- 9a0ec51236057e43d4176965cdd39ff0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037460" comment="k_deflt less than 2.4.21-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037461" comment="kernel-source less than 2.4.21-107"/>
		</criteria>
	</criteria>
	<!-- b0f1248576f4ba7a88b35a839945b272 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037462" comment="k_deflt less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037463" comment="k_itanium2-smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037464" comment="k_itanium2 less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037465" comment="k_smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037466" comment="kernel-source less than 2.4.21-144"/>
		</criteria>
	</criteria>
	<!-- e99e0bf873ed99011fadda29134213da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037467" comment="k_deflt less than 2.4.21-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037468" comment="kernel-source less than 2.4.21-102"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0077</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1edbffa2bbcd8c75a2d0e2d2ad287d33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037442" comment="kernel-iseries64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037443" comment="kernel-ppc64 less than 2.4.21-146"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037444" comment="kernel-source less than 2.4.21-146"/>
		</criteria>
	</criteria>
	<!-- 2f9b360b813a46151bbe467a34f53b2a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037445" comment="k_athlon less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037446" comment="k_deflt less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037447" comment="k_psmp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037448" comment="k_smp less than 2.4.19-349"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037449" comment="kernel-source less than 2.4.19.SuSE-349"/>
		</criteria>
	</criteria>
	<!-- 53bc5acb21c04e186b64731967c3f1fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037450" comment="k_athlon less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037451" comment="k_debug less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037452" comment="k_deflt less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037453" comment="k_psmp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037454" comment="k_smp less than 2.4.21-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037455" comment="kernel-source less than 2.4.21-190"/>
		</criteria>
	</criteria>
	<!-- 81063858996de55347cb1163516a80cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037456" comment="k_deflt less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037457" comment="k_numa less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037458" comment="k_smp less than 2.4.21-199"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037459" comment="kernel-source less than 2.4.21-199"/>
		</criteria>
	</criteria>
	<!-- 9a0ec51236057e43d4176965cdd39ff0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037460" comment="k_deflt less than 2.4.21-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037461" comment="kernel-source less than 2.4.21-107"/>
		</criteria>
	</criteria>
	<!-- b0f1248576f4ba7a88b35a839945b272 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037462" comment="k_deflt less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037463" comment="k_itanium2-smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037464" comment="k_itanium2 less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037465" comment="k_smp less than 2.4.21-144"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037466" comment="kernel-source less than 2.4.21-144"/>
		</criteria>
	</criteria>
	<!-- e99e0bf873ed99011fadda29134213da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037467" comment="k_deflt less than 2.4.21-102"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037468" comment="kernel-source less than 2.4.21-102"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040078" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0078</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- b225d4dc6e0c53998cfcc04dcb09a3dc -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037470" comment="mutt less than 1.4i-124"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037471" comment="mutt less than 1.4i-135"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037472" comment="mutt less than 1.4i-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037473" comment="mutt less than 1.4i-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037474" comment="mutt less than 1.4i-312"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037475" comment="mutt less than 1.4i-316"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037474" comment="mutt less than 1.4i-312"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037473" comment="mutt less than 1.4i-202"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037474" comment="mutt less than 1.4i-312"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037475" comment="mutt less than 1.4i-316"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040079" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0079</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079" source="CVE"/>
	<description>
	The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 217d709b60592a65aa3c9e49d1563098 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037477" comment="openssl-devel less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037478" comment="openssl-devel less than 0.9.6g-61"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037479" comment="openssl-devel less than 0.9.6g-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037480" comment="openssl-devel less than 0.9.6g-73"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037481" comment="openssl-devel less than 0.9.6g-82"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037477" comment="openssl-devel less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037481" comment="openssl-devel less than 0.9.6g-82"/>
			</criteria>
		</criteria></criteria>
	<!-- 8735c9921889b5c6d50ece0ad2391bb7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037482" comment="openssl less than 0.9.6a-84"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037484" comment="openssl less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037485" comment="openssl less than 0.9.6g-61"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037486" comment="openssl less than 0.9.6g-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037487" comment="openssl less than 0.9.6g-73"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037488" comment="openssl less than 0.9.6g-82"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037489" comment="openssl less than 0.9.6g-113"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037484" comment="openssl less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037488" comment="openssl less than 0.9.6g-82"/>
			</criteria>
		</criteria></criteria>
	<!-- 87a727a9a76c6c2b73fcb7966a6dc9ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040083" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0083</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083" source="CVE"/>
	<description>
	Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1f5bfacba77b82603470df47d563b843 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037490" comment="xf86 less than 4.0.3-72"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037492" comment="xf86 less than 4.2.0-178"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
			</criteria>
		</criteria></criteria>
	<!-- 3fe9a3a0106f1381e0194ac4a128d003 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037495" comment="XFree86 less than 4.3.0-119"/>
	</criteria>
	<!-- 6541fb41f5132aa080e9351692c2be6d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037496" comment="XFree86-server less than 4.3.0-121"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0084</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084" source="CVE"/>
	<description>
	Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1f5bfacba77b82603470df47d563b843 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037490" comment="xf86 less than 4.0.3-72"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037492" comment="xf86 less than 4.2.0-178"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
			</criteria>
		</criteria></criteria>
	<!-- 3fe9a3a0106f1381e0194ac4a128d003 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037495" comment="XFree86 less than 4.3.0-119"/>
	</criteria>
	<!-- 6541fb41f5132aa080e9351692c2be6d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037496" comment="XFree86-server less than 4.3.0-121"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040093" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0093</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0093" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ad3688c00000cc36b08db83f4cde236 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
		</criteria>
	</criteria>
	<!-- 5a3aef9029e35d5be5399bdb225ecdcd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037500" comment="xf86_glx less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037501" comment="xf86_glx less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037502" comment="xf86_glx less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037503" comment="xloader less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037504" comment="xloader less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037505" comment="xloader less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037506" comment="xmodules less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037507" comment="xmodules less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037508" comment="xmodules less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037500" comment="xf86_glx less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037502" comment="xf86_glx less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037503" comment="xloader less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037505" comment="xloader less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037506" comment="xmodules less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037508" comment="xmodules less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria></criteria>
	<!-- 7f45d0e5917c1fdccf5e6c65d1427a63 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037509" comment="xf86_glx less than 4.2.0-111"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037510" comment="xf86_glx less than 4.2.0-119"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0094</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0094" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ad3688c00000cc36b08db83f4cde236 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
		</criteria>
	</criteria>
	<!-- 5a3aef9029e35d5be5399bdb225ecdcd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037500" comment="xf86_glx less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037501" comment="xf86_glx less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037502" comment="xf86_glx less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037503" comment="xloader less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037504" comment="xloader less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037505" comment="xloader less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037506" comment="xmodules less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037507" comment="xmodules less than 4.2.0-181"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037508" comment="xmodules less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037500" comment="xf86_glx less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037502" comment="xf86_glx less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037497" comment="xf86_glx less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037503" comment="xloader less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037505" comment="xloader less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037498" comment="xloader less than 4.2.0-263"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037506" comment="xmodules less than 4.2.0-173"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037508" comment="xmodules less than 4.2.0-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037499" comment="xmodules less than 4.2.0-263"/>
			</criteria>
		</criteria></criteria>
	<!-- 7f45d0e5917c1fdccf5e6c65d1427a63 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037509" comment="xf86_glx less than 4.2.0-111"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037510" comment="xf86_glx less than 4.2.0-119"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040096" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0096</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0096" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 39860a7f3e767d06165e0053007502aa -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037511" comment="mod_python less than 2.7.10-1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037512" comment="mod_python less than 2.7.10-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037513" comment="mod_python less than 2.7.10-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037514" comment="mod_python less than 2.7.10-5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037515" comment="mod_python less than 2.7.10-7"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037515" comment="mod_python less than 2.7.10-7"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037513" comment="mod_python less than 2.7.10-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037514" comment="mod_python less than 2.7.10-5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037515" comment="mod_python less than 2.7.10-7"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0097</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097" source="CVE"/>
	<description>
	Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
	</description>
 </metadata>
<!-- 0256ec5e5498931a7e291e7ac792fff0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037516" comment="pwlib less than 1.4.9-67"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040106" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0106</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106" source="CVE"/>
	<description>
	Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.
	</description>
 </metadata>
<!-- 1f5bfacba77b82603470df47d563b843 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037490" comment="xf86 less than 4.0.3-72"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037492" comment="xf86 less than 4.2.0-178"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037491" comment="xf86 less than 4.2.0-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037493" comment="xf86 less than 4.2.0-190"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037494" comment="xf86 less than 4.2.0-257"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040108" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0108</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0108" source="CVE"/>
	<description>
	Unknown.
	</description>
 </metadata>
<!-- 23ae04025cad4488d0f426d4e5e853a7 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037517" comment="sysstat less than 4.0.3-155"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037518" comment="sysstat less than 4.0.3-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037519" comment="sysstat less than 4.0.3-183"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037520" comment="sysstat less than 4.0.3-228"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037521" comment="sysstat less than 4.0.3-86"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037522" comment="sysstat less than 4.0.3-97"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037520" comment="sysstat less than 4.0.3-228"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037518" comment="sysstat less than 4.0.3-169"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037519" comment="sysstat less than 4.0.3-183"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037520" comment="sysstat less than 4.0.3-228"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040109" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0109</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109" source="CVE"/>
	<description>
	Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 545715b66b8e47a47feb0b8e5398415f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037523" comment="k_athlon less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037524" comment="k_deflt less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037525" comment="k_psmp less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037526" comment="k_smp less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037527" comment="kernel-source less than 2.4.19.SuSE-353"/>
		</criteria>
	</criteria>
	<!-- 7e26c6123a27d9f3e3ad4b5009cee4fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037528" comment="k_athlon less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037529" comment="k_debug less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037530" comment="k_deflt less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037531" comment="k_psmp less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037532" comment="k_smp less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037533" comment="kernel-source less than 2.4.21-203"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040110" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0110</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110" source="CVE"/>
	<description>
	Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 296ba2b642bc398bf6c293560c6e03c4 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037534" comment="libxml2-devel less than 2.4.23-244"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037535" comment="libxml2 less than 2.4.23-244"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037536" comment="libxml2-devel less than 2.4.23-243"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037537" comment="libxml2 less than 2.4.23-243"/>
			</criteria>
		</criteria></criteria>
	<!-- 68c6d6b9aacc050b5742b748530473bc -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037538" comment="libxml2 less than 2.4.23-117"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037539" comment="libxml2 less than 2.4.23-123"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037540" comment="libxml2 less than 2.4.23-192"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037541" comment="libxml2 less than 2.4.23-224"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037542" comment="libxml2 less than 2.4.23-90"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037543" comment="libxml2 less than 2.4.23-97"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037544" comment="libxml2 less than 2.4.23-223"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037541" comment="libxml2 less than 2.4.23-224"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037539" comment="libxml2 less than 2.4.23-123"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037540" comment="libxml2 less than 2.4.23-192"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037541" comment="libxml2 less than 2.4.23-224"/>
			</criteria>
		</criteria></criteria>
	<!-- 89932fad5647a92eea81575a477702ad -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037545" comment="libxml2-devel less than 2.4.23-118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037546" comment="libxml2-devel less than 2.4.23-124"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037547" comment="libxml2-devel less than 2.4.23-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037548" comment="libxml2-devel less than 2.4.23-225"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037549" comment="libxml2-devel less than 2.4.23-91"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037550" comment="libxml2-devel less than 2.4.23-98"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037551" comment="libxml2-devel less than 2.4.23-223"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037548" comment="libxml2-devel less than 2.4.23-225"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037546" comment="libxml2-devel less than 2.4.23-124"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037547" comment="libxml2-devel less than 2.4.23-193"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037548" comment="libxml2-devel less than 2.4.23-225"/>
			</criteria>
		</criteria></criteria>
	<!-- 969e1829d7e212fea47d4cf82da0bb2d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032410" comment="libxml2-32bit less than 9-200412202049"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032411" comment="libxml2-32bit less than 9-200412202205"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032412" comment="libxml2-64bit less than 9-200412202113"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030406" comment="libxml2-devel less than 2.6.7-28.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032413" comment="libxml2-x86 less than 9-200412202214"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030407" comment="libxml2 less than 2.6.7-28.7"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030406" comment="libxml2-devel less than 2.6.7-28.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030407" comment="libxml2 less than 2.6.7-28.7"/>
			</criteria>
		</criteria></criteria>
	<!-- a9e2b82d8b69745daaaae4de8270acf0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030408" comment="libxml2-python less than 2.6.7-46.7"/>
	</criteria>
	<!-- ebcaf61f6debd12131a1753d095345dd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032414" comment="libxml-32bit less than 9-200412202049"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032415" comment="libxml-32bit less than 9-200412202205"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032416" comment="libxml-64bit less than 9-200412202113"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030409" comment="libxml-devel less than 1.8.17-366.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032417" comment="libxml-x86 less than 9-200412202214"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030410" comment="libxml less than 1.8.17-366.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037552" comment="libxml-devel less than 1.8.17-370"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037553" comment="libxml-devel less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037555" comment="libxml less than 1.8.17-370"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037556" comment="libxml less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030409" comment="libxml-devel less than 1.8.17-366.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030410" comment="libxml less than 1.8.17-366.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037553" comment="libxml-devel less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037556" comment="libxml less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040112" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0112</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112" source="CVE"/>
	<description>
	The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 217d709b60592a65aa3c9e49d1563098 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037477" comment="openssl-devel less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037478" comment="openssl-devel less than 0.9.6g-61"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037479" comment="openssl-devel less than 0.9.6g-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037480" comment="openssl-devel less than 0.9.6g-73"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037481" comment="openssl-devel less than 0.9.6g-82"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037477" comment="openssl-devel less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037481" comment="openssl-devel less than 0.9.6g-82"/>
			</criteria>
		</criteria></criteria>
	<!-- 8735c9921889b5c6d50ece0ad2391bb7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037482" comment="openssl less than 0.9.6a-84"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037484" comment="openssl less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037485" comment="openssl less than 0.9.6g-61"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037486" comment="openssl less than 0.9.6g-62"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037487" comment="openssl less than 0.9.6g-73"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037488" comment="openssl less than 0.9.6g-82"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037489" comment="openssl less than 0.9.6g-113"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037484" comment="openssl less than 0.9.6g-130"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037488" comment="openssl less than 0.9.6g-82"/>
			</criteria>
		</criteria></criteria>
	<!-- 87a727a9a76c6c2b73fcb7966a6dc9ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037476" comment="openssl-devel less than 0.9.6g-114"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037483" comment="openssl less than 0.9.6g-114"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0174</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174" source="CVE"/>
	<description>
	Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
	</description>
 </metadata>
<!-- b0ad3afc1961097e6bb58010b7dba2c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036808" comment="apache-devel less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036809" comment="apache-devel less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036810" comment="apache-devel less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036812" comment="apache less than 1.3.19-153"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036813" comment="apache less than 1.3.19-154"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036814" comment="apache less than 1.3.20-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036816" comment="mod_ssl less than 2.8.3-74"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036817" comment="mod_ssl less than 2.8.3-75"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036818" comment="mod_ssl less than 2.8.4-85"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036811" comment="apache-devel less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036815" comment="apache less than 1.3.24-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036819" comment="mod_ssl less than 2.8.8-24"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036820" comment="apache-devel less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036821" comment="apache less than 1.3.26-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036822" comment="mod_ssl less than 2.8.10-157"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0175</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0175" source="CVE"/>
	<description>
	Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.
	</description>
 </metadata>
<!-- 16f31dfee8c851b417ec03480ed86abc -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037184" comment="openssh less than 3.4p1-118"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037558" comment="openssh less than 3.4p1-123"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037559" comment="openssh less than 3.4p1-138"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037560" comment="openssh less than 3.4p1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037561" comment="openssh less than 3.4p1-237"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037562" comment="openssh less than 3.4p1-263"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037563" comment="openssh less than 3.4p1-264"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037562" comment="openssh less than 3.4p1-263"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037560" comment="openssh less than 3.4p1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037561" comment="openssh less than 3.4p1-237"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037562" comment="openssh less than 3.4p1-263"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0176</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176" source="CVE"/>
	<description>
	Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 08522619fdb66569547c8e86fdbf5182 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
	</criteria>
	<!-- a8320fd0958373a8ae379ba8182a92b0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037565" comment="ethereal less than 0.10.3-5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037566" comment="ethereal less than 0.10.3-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037568" comment="ethereal less than 0.10.3-8"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0179</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0179" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8e48863380af6c1b5bb3fbaa945b7c79 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037570" comment="OpenOffice_org-cs less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037571" comment="OpenOffice_org-de less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037572" comment="OpenOffice_org-en-help less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037573" comment="OpenOffice_org-en less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037574" comment="OpenOffice_org-fr less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037575" comment="OpenOffice_org-it less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037576" comment="OpenOffice_org-nl less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037577" comment="OpenOffice_org less than 1.1-97"/>
		</criteria>
	</criteria>
	<!-- c63e7c2eac14e82a0bc416cde4eb3137 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037578" comment="sitecopy less than 0.11.4-1024"/>
	</criteria>
	<!-- ea6e2b05625038c203d34ea65e1f4e47 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037579" comment="cadaver less than 0.19.1-156"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0180</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0180" source="CVE"/>
	<description>
	The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.
	</description>
 </metadata>
<!-- 1f97ace7fcd0f10d0bf230724d89769b -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037580" comment="cvs less than 1.11.1p1-107"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037581" comment="cvs less than 1.11.1p1-131"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037582" comment="cvs less than 1.11.1p1-197"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037583" comment="cvs less than 1.11.1p1-205"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036800" comment="cvs less than 1.11.1p1-235"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037584" comment="cvs less than 1.11.1p1-326"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037584" comment="cvs less than 1.11.1p1-326"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037582" comment="cvs less than 1.11.1p1-197"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036800" comment="cvs less than 1.11.1p1-235"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037584" comment="cvs less than 1.11.1p1-326"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0181</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0181" source="CVE"/>
	<description>
	The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 545715b66b8e47a47feb0b8e5398415f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037523" comment="k_athlon less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037524" comment="k_deflt less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037525" comment="k_psmp less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037526" comment="k_smp less than 2.4.19-353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037527" comment="kernel-source less than 2.4.19.SuSE-353"/>
		</criteria>
	</criteria>
	<!-- 7e26c6123a27d9f3e3ad4b5009cee4fe -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037528" comment="k_athlon less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037529" comment="k_debug less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037530" comment="k_deflt less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037531" comment="k_psmp less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037532" comment="k_smp less than 2.4.21-203"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037533" comment="kernel-source less than 2.4.21-203"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0183</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183" source="CVE"/>
	<description>
	TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
	</description>
 </metadata>
<!-- 751866766ed5db6c6597d06eee7c8bcf -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037585" comment="tcpdump less than 3.7.1-139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037586" comment="tcpdump less than 3.7.1-175"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037587" comment="tcpdump less than 3.7.1-187"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037588" comment="tcpdump less than 3.7.1-236"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037589" comment="tcpdump less than 3.7.1-356"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037590" comment="tcpdump less than 3.7.1-371"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037591" comment="tcpdump less than 3.7.1-372"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037590" comment="tcpdump less than 3.7.1-371"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037588" comment="tcpdump less than 3.7.1-236"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037589" comment="tcpdump less than 3.7.1-356"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037590" comment="tcpdump less than 3.7.1-371"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040226" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0226</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0226" source="CVE"/>
	<description>
	Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
	</description>
 </metadata>
<!-- 323303ede946c7ebf37f893aa383e0a2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037592" comment="mc less than 4.5.51-180"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037593" comment="mc less than 4.5.55-758"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040231" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0231</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0231" source="CVE"/>
	<description>
	Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
	</description>
 </metadata>
<!-- 323303ede946c7ebf37f893aa383e0a2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037592" comment="mc less than 4.5.51-180"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037593" comment="mc less than 4.5.55-758"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040232" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0232</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0232" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
	</description>
 </metadata>
<!-- 323303ede946c7ebf37f893aa383e0a2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037592" comment="mc less than 4.5.51-180"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037593" comment="mc less than 4.5.55-758"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040233" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0233</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0233" source="CVE"/>
	<description>
	Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.
	</description>
 </metadata>
<!-- b4c0cbcb1e8636fcf7dd55a533c28222 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037594" comment="utempter less than 0.5.2-391"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037595" comment="utempter less than 0.5.2-392"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037594" comment="utempter less than 0.5.2-391"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037594" comment="utempter less than 0.5.2-391"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040234" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0234</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 318ecbeaba3da8e6837d2c3eaaedf374 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037596" comment="lha less than 1.14i-556"/>
	</criteria>
	<!-- c9d948a1f73aea56501154c51345b7db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037596" comment="lha less than 1.14i-556"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040235" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0235</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0235" source="CVE"/>
	<description>
	Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 318ecbeaba3da8e6837d2c3eaaedf374 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037596" comment="lha less than 1.14i-556"/>
	</criteria>
	<!-- c9d948a1f73aea56501154c51345b7db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037596" comment="lha less than 1.14i-556"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040365" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0365</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365" source="CVE"/>
	<description>
	The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 08522619fdb66569547c8e86fdbf5182 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
	</criteria>
	<!-- a8320fd0958373a8ae379ba8182a92b0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037565" comment="ethereal less than 0.10.3-5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037566" comment="ethereal less than 0.10.3-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037568" comment="ethereal less than 0.10.3-8"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040367" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0367</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367" source="CVE"/>
	<description>
	Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 08522619fdb66569547c8e86fdbf5182 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
	</criteria>
	<!-- a8320fd0958373a8ae379ba8182a92b0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037565" comment="ethereal less than 0.10.3-5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037566" comment="ethereal less than 0.10.3-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037568" comment="ethereal less than 0.10.3-8"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037564" comment="ethereal less than 0.10.3-10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037567" comment="ethereal less than 0.10.3-7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037569" comment="ethereal less than 0.10.3-9"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040371" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0371</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0371" source="CVE"/>
	<description>
	Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
	</description>
 </metadata>
<!-- c9e1b28a0689b282b00614ce00e02260 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037597" comment="heimdal less than 0.3e-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037598" comment="heimdal less than 0.4d-143"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036730" comment="slos-1.0 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037597" comment="heimdal less than 0.3e-100"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037599" comment="heimdal less than 0.4e-401"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040386" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0386</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0386" source="CVE"/>
	<description>
	Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
	</description>
 </metadata>
<!-- 67347d7fe6c991fef81b3e288481a6a6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037600" comment="MPlayer less than 0.90rc4-260"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040394" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0394</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0394" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0394" source="CVE"/>
	<description>
	A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 38b381641a9b8b178bc566777b7d2ab2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037601" comment="kernel-iseries64 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037602" comment="kernel-ppc64 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- 4baf51e74c66ad8e924f71811dec51f2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037604" comment="k_athlon less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037605" comment="k_deflt less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037606" comment="k_psmp less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037607" comment="k_smp less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037608" comment="kernel-source less than 2.4.19.SuSE-355"/>
		</criteria>
	</criteria>
	<!-- 665565dbb2c37d261e5eaa9fd51c857e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037610" comment="k_numa less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- 9309e7d63fd36f8037c4e74a838af898 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037612" comment="k_itanium2-smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037613" comment="k_itanium2 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- e0f7a5e9d5fc56fa09f31a35a6dc48ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037614" comment="k_athlon less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037615" comment="k_debug less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037616" comment="k_psmp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040398" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0398</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0398" source="CVE"/>
	<description>
	Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8e48863380af6c1b5bb3fbaa945b7c79 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037570" comment="OpenOffice_org-cs less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037571" comment="OpenOffice_org-de less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037572" comment="OpenOffice_org-en-help less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037573" comment="OpenOffice_org-en less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037574" comment="OpenOffice_org-fr less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037575" comment="OpenOffice_org-it less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037576" comment="OpenOffice_org-nl less than 1.1-97"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037577" comment="OpenOffice_org less than 1.1-97"/>
		</criteria>
	</criteria>
	<!-- c63e7c2eac14e82a0bc416cde4eb3137 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037578" comment="sitecopy less than 0.11.4-1024"/>
	</criteria>
	<!-- ea6e2b05625038c203d34ea65e1f4e47 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037579" comment="cadaver less than 0.19.1-156"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040409" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0409</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0409" source="CVE"/>
	<description>
	Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 56de914abda286ddeda74f85a2fd4a5e -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037617" comment="xchat less than 1.8.10-193"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040411" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0411</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0411" source="CVE"/>
	<description>
	The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
	</description>
 </metadata>
<!-- aee0c8dba93a0a00a64c933c299be4ba -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037618" comment="kdelibs3-32bit less than 8.1-71"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037619" comment="kdelibs3 less than 3.0.3-205"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037620" comment="kdelibs3 less than 3.1.1-140"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037619" comment="kdelibs3 less than 3.0.3-205"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040415" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0415</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0415" source="CVE"/>
	<description>
	Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 720607e9f5ab4b2feb95882433062944 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037621" comment="k_athlon less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037622" comment="k_debug less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037623" comment="k_deflt less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037624" comment="k_psmp less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037625" comment="k_smp less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037626" comment="kernel-source less than 2.4.21-238"/>
		</criteria>
	</criteria>
	<!-- d016ebe4c02682e8ec038f53b83ddc41 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037627" comment="k_athlon less than 2.4.19-363"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037628" comment="k_deflt less than 2.4.19-363"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037629" comment="k_psmp less than 2.4.19-363"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037630" comment="k_smp less than 2.4.19-363"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037631" comment="kernel-source less than 2.4.19.SuSE-363"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040416" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0416</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0416" source="CVE"/>
	<description>
	Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 10290f9d0abbbc20942bb957a4e9fb66 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037633" comment="cvs less than 1.11.1p1-332"/>
		</criteria></criteria>
	<!-- d9956e45cbb7335e0d1b8da58a06ad21 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037634" comment="cvs less than 1.11.1p1-334"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040417" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0417</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0417" source="CVE"/>
	<description>
	Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 10290f9d0abbbc20942bb957a4e9fb66 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037633" comment="cvs less than 1.11.1p1-332"/>
		</criteria></criteria>
	<!-- d9956e45cbb7335e0d1b8da58a06ad21 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037634" comment="cvs less than 1.11.1p1-334"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040418" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0418</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0418" source="CVE"/>
	<description>
	serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 10290f9d0abbbc20942bb957a4e9fb66 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037633" comment="cvs less than 1.11.1p1-332"/>
		</criteria></criteria>
	<!-- d9956e45cbb7335e0d1b8da58a06ad21 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037632" comment="cvs less than 1.11-248"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037634" comment="cvs less than 1.11.1p1-334"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040424" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0424</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0424" source="CVE"/>
	<description>
	Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 38b381641a9b8b178bc566777b7d2ab2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037601" comment="kernel-iseries64 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037602" comment="kernel-ppc64 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- 4baf51e74c66ad8e924f71811dec51f2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037604" comment="k_athlon less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037605" comment="k_deflt less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037606" comment="k_psmp less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037607" comment="k_smp less than 2.4.19-355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037608" comment="kernel-source less than 2.4.19.SuSE-355"/>
		</criteria>
	</criteria>
	<!-- 665565dbb2c37d261e5eaa9fd51c857e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037610" comment="k_numa less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- 9309e7d63fd36f8037c4e74a838af898 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037612" comment="k_itanium2-smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037613" comment="k_itanium2 less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
	<!-- e0f7a5e9d5fc56fa09f31a35a6dc48ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037614" comment="k_athlon less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037615" comment="k_debug less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037609" comment="k_deflt less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037616" comment="k_psmp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037611" comment="k_smp less than 2.4.21-215"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037603" comment="kernel-source less than 2.4.21-215"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040426" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0426</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA64</platform>
		<platform>SuSE Linux Enterprise Server 7 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 7 for PowerPC</platform>
		<platform>SuSE Linux Enterprise Server 7 for S/390 and zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426" source="CVE"/>
	<description>
	rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.
	</description>
 </metadata>
<!-- 6e6998547a9f98ffd0a0c2dd2e50939d -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037635" comment="rsync less than 2.6.2-14"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037635" comment="rsync less than 2.6.2-14"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037636" comment="rsync less than 2.6.2-11"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040452" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0452</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452" source="CVE"/>
	<description>
	Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.
	</description>
 </metadata>
<!-- 7e6cf48cf7a796f79176269c2c18b8df -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032418" comment="perl-32bit less than 9-200502051955"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032419" comment="perl-32bit less than 9-200502060348"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032420" comment="perl-64bit less than 9-200502060420"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032421" comment="perl-x86 less than 9-200502051945"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037637" comment="perl less than 5.8.0-201"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040457" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0457</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0457" source="CVE"/>
	<description>
	The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
	</description>
 </metadata>
<!-- 42f8c8e60d600a62b2fa48ac529c929a -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032422" comment="mysql less than 4.0.18-32.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037638" comment="mysql less than 3.23.52-124"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040460" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0460</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0460" source="CVE"/>
	<description>
	Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.
	</description>
 </metadata>
<!-- b4da89613e051f3886cbf3c95f44042f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037639" comment="dhcp-server less than 3.0.1rc9-144"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040461" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0461</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0461" source="CVE"/>
	<description>
	The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.
	</description>
 </metadata>
<!-- b4da89613e051f3886cbf3c95f44042f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037639" comment="dhcp-server less than 3.0.1rc9-144"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040492" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0492</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492" source="CVE"/>
	<description>
	Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
	</description>
 </metadata>
<!-- c6e2744b39469696f324d3ea05bc70da -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037640" comment="apache less than 1.3.26-159"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040494" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0494</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0494" source="CVE"/>
	<description>
	Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 50802e51d74cd2da860a412b1f03a9e5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032423" comment="mc less than 4.6.0-324.7"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037641" comment="mc less than 4.5.55-760"/>
		</criteria></criteria>
	<!-- 6e8b9da54a654fd68b754c2b999808d9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032424" comment="gnome-vfs less than 1.0.5-806.7"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037642" comment="gnome-vfs less than 1.0.5-822"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria></criteria>
	<!-- 7f86db7e0c063af0a4b3738c4b6d26be -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037644" comment="gnome-vfs2 less than 2.2.1-161"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037645" comment="gnome-vfs2 less than 2.0.2-271"/>
		</criteria></criteria>
	<!-- 9f1ac1f133c3a545b4b657d4eabe53ec -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037646" comment="gnome-vfs2 less than 2.2.1-157"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037647" comment="gnome-vfs2 less than 2.0.2-269"/>
		</criteria></criteria>
	<!-- a9b2b8c3a049831dfe42a9cc69112c52 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032425" comment="gnome-vfs2-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032426" comment="gnome-vfs2-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032427" comment="gnome-vfs2-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030412" comment="gnome-vfs2-32bit less than 9-200504132212"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030413" comment="gnome-vfs2-doc less than 2.6.1-6.23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030414" comment="gnome-vfs2 less than 2.6.1-6.23"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria></criteria>
	<!-- bdd3b754fc83ccf00b43592ca115175a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032430" comment="gnome-vfs less than 1.0.5-806.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037648" comment="gnome-vfs less than 1.0.5-814"/>
		</criteria></criteria>
	<!-- c114346c1dfffbd81602370d1f2cb899 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037650" comment="gnome-vfs2-doc less than 2.2.1-159"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037651" comment="gnome-vfs2 less than 2.2.1-159"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037653" comment="gnome-vfs2-doc less than 2.2.5-128"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037654" comment="gnome-vfs2 less than 2.2.5-128"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037656" comment="gnome-vfs2-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037658" comment="gnome-vfs2-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037659" comment="gnome-vfs2-doc less than 2.6.1-38.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037660" comment="gnome-vfs2 less than 2.6.1-38.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037662" comment="gnome-vfs2-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037663" comment="gnome-vfs2-doc less than 2.10.0-14.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037664" comment="gnome-vfs2 less than 2.10.0-14.2"/>
			</criteria>
		</criteria></criteria>
	<!-- cb5dd06c287acb5bb44404f77353e379 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032424" comment="gnome-vfs less than 1.0.5-806.7"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037665" comment="gnome-vfs less than 1.0.5-808.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037666" comment="gnome-vfs less than 1.0.5-816.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040495" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0495</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0495" source="CVE"/>
	<description>
	Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040496" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0496</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0496" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0496" source="CVE"/>
	<description>
	Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040497" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0497</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0497" source="CVE"/>
	<description>
	Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040504" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0504</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0504" source="CVE"/>
	<description>
	Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
	</description>
 </metadata>
<!-- 0d593232af7f97e396db01b012979d6f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032431" comment="ethereal less than 0.10.3-15.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037672" comment="ethereal less than 0.10.3-24"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040505" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0505</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0505" source="CVE"/>
	<description>
	The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
	</description>
 </metadata>
<!-- 0d593232af7f97e396db01b012979d6f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032431" comment="ethereal less than 0.10.3-15.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037672" comment="ethereal less than 0.10.3-24"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040506" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0506</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0506" source="CVE"/>
	<description>
	The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.
	</description>
 </metadata>
<!-- 0d593232af7f97e396db01b012979d6f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032431" comment="ethereal less than 0.10.3-15.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037672" comment="ethereal less than 0.10.3-24"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040507" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0507</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0507" source="CVE"/>
	<description>
	Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
	</description>
 </metadata>
<!-- 0d593232af7f97e396db01b012979d6f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032431" comment="ethereal less than 0.10.3-15.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037672" comment="ethereal less than 0.10.3-24"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040519" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0519</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-0519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0519" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
	</description>
 </metadata>
<!-- 7d6fd9f2af96c64598d90b3151ec4f48 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037673" comment="squirrelmail less than 1.4.1-246"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037674" comment="squirrelmail less than 1.4.2-55.11"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037675" comment="squirrelmail less than 1.4.2-59.9"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037676" comment="squirrelmail less than 1.4.2-64.7"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040521" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0521</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-0521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0521" source="CVE"/>
	<description>
	SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
	</description>
 </metadata>
<!-- 327ed8a0b6932e30e99ded3d5a50e811 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037677" comment="squirrelmail less than 1.4.1-241"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037678" comment="squirrelmail less than 1.4.2-55.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037679" comment="squirrelmail less than 1.4.2-59.4"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037680" comment="squirrelmail less than 1.4.2-64.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040535" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0535</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0535" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0535" source="CVE"/>
	<description>
	The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory.  NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0547</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0547" source="CVE"/>
	<description>
	Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).
	</description>
 </metadata>
<!-- dce69ee8acabb648b2e0a7cf86f2e501 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037681" comment="postgresql-odbc less than 7.2.2-178"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040554" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0554</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0554" source="CVE"/>
	<description>
	Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 010aaa8f96770a94c609bb7f997ae75c -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037682" comment="k_athlon less than 2.4.21-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037683" comment="k_debug less than 2.4.21-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037684" comment="k_deflt less than 2.4.21-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037685" comment="k_psmp less than 2.4.21-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037686" comment="k_smp less than 2.4.21-226"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037687" comment="kernel-source less than 2.4.21-226"/>
		</criteria>
	</criteria>
	<!-- 720607e9f5ab4b2feb95882433062944 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037621" comment="k_athlon less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037622" comment="k_debug less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037623" comment="k_deflt less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037624" comment="k_psmp less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037625" comment="k_smp less than 2.4.21-238"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037626" comment="kernel-source less than 2.4.21-238"/>
		</criteria>
	</criteria>
	<!-- bd39456bc2f4bc41344e444e01a44ce4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037688" comment="k_athlon less than 2.4.19-358"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037689" comment="k_deflt less than 2.4.19-358"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037690" comment="k_psmp less than 2.4.19-358"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037691" comment="k_smp less than 2.4.19-358"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037692" comment="kernel-source less than 2.4.19.SuSE-358"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040557" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0557</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0557" source="CVE"/>
	<description>
	Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
	</description>
 </metadata>
<!-- 5cf776b56f244a371bbf29c4a68630b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037693" comment="sox less than 12.17.3-688"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040558" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0558</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0558" source="CVE"/>
	<description>
	The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- c5b0b422e8d7e48a178aced6fe723b75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032432" comment="cups-client less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032433" comment="cups-devel less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032434" comment="cups-libs-32bit less than 9-200408311758"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032435" comment="cups-libs-32bit less than 9-200408311952"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032436" comment="cups-libs-64bit less than 9-200408312018"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032437" comment="cups-libs-x86 less than 9-200408311747"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032438" comment="cups-libs less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032439" comment="cups less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032440" comment="foomatic-filters less than 3.0.1-41.6"/>
		</criteria>
	</criteria>
	<!-- f413b4212c37a07d8cb7616de4485344 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037694" comment="cups-client less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037695" comment="cups-devel less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037696" comment="cups-libs less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037697" comment="cups less than 1.1.15-167"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037698" comment="cups-client less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037699" comment="cups-devel less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037700" comment="cups-libs less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037701" comment="cups less than 1.1.15-170"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040592" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0592</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0592" source="CVE"/>
	<description>
	The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040597" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0597</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597" source="CVE"/>
	<description>
	Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 00393c0dc2fce8d1f7038ea22e91897d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037702" comment="rrdtool less than 1.0.39-168"/>
	</criteria>
	<!-- 4fcbb613930b89b0575aefd84e562bb7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037703" comment="libpng less than 1.2.4-119"/>
	</criteria>
	<!-- d4c82e8ce1131422a26739977059cd46 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032441" comment="libpng-32bit less than 9-200407192204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032442" comment="libpng-32bit less than 9-200407192329"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032443" comment="libpng-64bit less than 9-200407211228"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032444" comment="libpng-x86 less than 9-200407192328"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032445" comment="libpng less than 1.2.5-182.7"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037705" comment="libpng less than 1.2.4-116"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037706" comment="libpng less than 1.2.4-115"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040598" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0598</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0598" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0598" source="CVE"/>
	<description>
	The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 00393c0dc2fce8d1f7038ea22e91897d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037702" comment="rrdtool less than 1.0.39-168"/>
	</criteria>
	<!-- 4fcbb613930b89b0575aefd84e562bb7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037703" comment="libpng less than 1.2.4-119"/>
	</criteria>
	<!-- d4c82e8ce1131422a26739977059cd46 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032441" comment="libpng-32bit less than 9-200407192204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032442" comment="libpng-32bit less than 9-200407192329"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032443" comment="libpng-64bit less than 9-200407211228"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032444" comment="libpng-x86 less than 9-200407192328"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032445" comment="libpng less than 1.2.5-182.7"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037705" comment="libpng less than 1.2.4-116"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037706" comment="libpng less than 1.2.4-115"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040599" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0599</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599" source="CVE"/>
	<description>
	Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 00393c0dc2fce8d1f7038ea22e91897d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037702" comment="rrdtool less than 1.0.39-168"/>
	</criteria>
	<!-- 4fcbb613930b89b0575aefd84e562bb7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037703" comment="libpng less than 1.2.4-119"/>
	</criteria>
	<!-- d4c82e8ce1131422a26739977059cd46 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032441" comment="libpng-32bit less than 9-200407192204"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032442" comment="libpng-32bit less than 9-200407192329"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032443" comment="libpng-64bit less than 9-200407211228"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032444" comment="libpng-x86 less than 9-200407192328"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032445" comment="libpng less than 1.2.5-182.7"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037704" comment="libpng less than 2.1.0.10-63"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037705" comment="libpng less than 1.2.4-116"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037706" comment="libpng less than 1.2.4-115"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040600" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0600</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0600" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0600" source="CVE"/>
	<description>
	Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
	</description>
 </metadata>
<!-- 9ceab98ac3fc612da6b2a294ba2c43c5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032446" comment="libsmbclient-32bit less than 9-200407211117"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032447" comment="libsmbclient-32bit less than 9-200407211155"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032448" comment="libsmbclient-64bit less than 9-200407211228"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032449" comment="libsmbclient-devel less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032450" comment="libsmbclient less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032451" comment="samba-client less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032452" comment="samba-pdb less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032453" comment="samba-python less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032454" comment="samba-winbind less than 3.0.4-1.27"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032455" comment="samba less than 3.0.4-1.27"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040626" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0626</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0626" source="CVE"/>
	<description>
	The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.
	</description>
 </metadata>
<!-- 7b94d057e7afe6258ef70a1a8138fb84 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037667" comment="k_athlon less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037668" comment="k_deflt less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037669" comment="k_psmp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037670" comment="k_smp less than 2.4.19-360"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037671" comment="kernel-source less than 2.4.19.SuSE-360"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040630" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0630</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0630" source="CVE"/>
	<description>
	The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is provided to the uudecode command.
	</description>
 </metadata>
<!-- 22f606e0a125a66339787ef7b45e6387 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032456" comment="acroread less than 5.09-4.2"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037707" comment="acroread less than 5.09-5"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040631" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0631</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0631" source="CVE"/>
	<description>
	Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.
	</description>
 </metadata>
<!-- 22f606e0a125a66339787ef7b45e6387 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032456" comment="acroread less than 5.09-4.2"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037707" comment="acroread less than 5.09-5"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040633" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0633</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0633" source="CVE"/>
	<description>
	The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.
	</description>
 </metadata>
<!-- 05f602a488b931557571a0a726de1aed -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032457" comment="ethereal less than 0.10.3-15.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2-vpn is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040634" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0634</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0634" source="CVE"/>
	<description>
	The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
	</description>
 </metadata>
<!-- 05f602a488b931557571a0a726de1aed -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032457" comment="ethereal less than 0.10.3-15.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2-vpn is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040635" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0635</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0635" source="CVE"/>
	<description>
	The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
	</description>
 </metadata>
<!-- 05f602a488b931557571a0a726de1aed -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032457" comment="ethereal less than 0.10.3-15.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2-vpn is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037708" comment="ethereal less than 0.10.3-20"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040656" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0656</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0656" source="CVE"/>
	<description>
	The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
	</description>
 </metadata>
<!-- 751d49dd2256184e10d64ee814ad9b7d -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032458" comment="pure-ftpd less than 1.0.18-39.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037709" comment="pure-ftpd less than 1.0.12-232"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040686" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0686</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686" source="CVE"/>
	<description>
	Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 57309df0c14278ff81362b7f31a4ca0d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037710" comment="samba-client less than 2.2.8a-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037711" comment="samba less than 2.2.8a-218"/>
		</criteria>
	</criteria>
	<!-- 9ceab98ac3fc612da6b2a294ba2c43c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032446" comment="libsmbclient-32bit less than 9-200407211117"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032447" comment="libsmbclient-32bit less than 9-200407211155"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032448" comment="libsmbclient-64bit less than 9-200407211228"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032449" comment="libsmbclient-devel less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032450" comment="libsmbclient less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032451" comment="samba-client less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032452" comment="samba-pdb less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032453" comment="samba-python less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032454" comment="samba-winbind less than 3.0.4-1.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032455" comment="samba less than 3.0.4-1.27"/>
		</criteria>
	</criteria>
	<!-- feb4dfd2e0ba57fdfe3843911180e9c6 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037710" comment="samba-client less than 2.2.8a-218"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037712" comment="samba-vscan less than 0.3.2a-271"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037711" comment="samba less than 2.2.8a-218"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040687" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0687</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux 8.1 for IA32</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0687" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1c6cfc49def629c55e85e6a51eb19b44 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032459" comment="openmotif-devel-32bit less than 9-200410031617"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032460" comment="openmotif-devel-32bit less than 9-200410031928"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032461" comment="openmotif-devel-64bit less than 9-200410031619"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037713" comment="openmotif-devel less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
			</criteria>
		</criteria></criteria>
	<!-- 4f0e8a935331771d82d672529137b021 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037715" comment="xshared less than 4.2.0-269"/>
	</criteria>
	<!-- 5fc836c604fb00d163180bddb1be43c2 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032464" comment="XFree86-libs-32bit less than 9-200411100109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032465" comment="XFree86-libs-32bit less than 9-200411100704"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032466" comment="XFree86-libs-64bit less than 9-200411100528"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032467" comment="XFree86-libs-x86 less than 9-200411100318"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030415" comment="XFree86-libs less than 4.3.99.902-43.35.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037716" comment="XFree86-libs less than 4.3.0-132"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030415" comment="XFree86-libs less than 4.3.99.902-43.35.3"/>
		</criteria></criteria>
	<!-- 7eda55a9d7bcfbc970fb40b2a369d418 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037717" comment="xorg-x11-devel-32bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037718" comment="xorg-x11-devel less than 6.9.0-50.45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037717" comment="xorg-x11-devel-32bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037719" comment="xorg-x11-devel-64bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037718" comment="xorg-x11-devel less than 6.9.0-50.45"/>
			</criteria>
		</criteria></criteria>
	<!-- 874818c6fcf8ec787277497858d0c8f4 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037720" comment="xshared less than 4.2.0-267"/>
	</criteria>
	<!-- 99f082dd483ac0d81aa4ef9a2301d420 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032468" comment="openmotif-devel-32bit less than 9-200410081851"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032469" comment="openmotif-devel-32bit less than 9-200410082201"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032470" comment="openmotif-devel-64bit less than 9-200410082105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032471" comment="openmotif-libs-32bit less than 9-200410081851"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032472" comment="openmotif-libs-32bit less than 9-200410082201"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032473" comment="openmotif-libs-64bit less than 9-200410082105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032474" comment="openmotif-libs less than 2.2.2-519.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
		</criteria>
	</criteria>
	<!-- b56c5555fff84ee828ea63a9bb9542f1 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032475" comment="openmotif21-libs less than 2.1.30MLI4-119.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037721" comment="openmotif21-libs less than 2.1.30MLI4-122"/>
		</criteria></criteria>
	<!-- ed9788410744ec97483978da5304464c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032476" comment="XFree86-libs-32bit less than 9-200409151952"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032477" comment="XFree86-libs-32bit less than 9-200409161634"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032478" comment="XFree86-libs-64bit less than 9-200409152030"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032479" comment="XFree86-libs-x86 less than 9-200409152035"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032480" comment="XFree86-libs less than 4.3.99.902-43.31"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037722" comment="XFree86-libs less than 4.3.0-128"/>
		</criteria></criteria>
	<!-- f9386d673ffafe49ce62f85b188b3990 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
	</criteria>
	<!-- fa8ab3ca18be2f2ad1cf95944e137087 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037723" comment="suse81 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037724" comment="openmotif-demo less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037713" comment="openmotif-devel less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037725" comment="openmotif-demo less than 2.2.2-524"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037726" comment="openmotif-devel less than 2.2.2-524"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037727" comment="openmotif less than 2.2.2-524"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037728" comment="openmotif-demo less than 2.2.2-523"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037729" comment="openmotif-devel-32bit less than 9.0-4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037730" comment="openmotif-devel less than 2.2.2-523"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037731" comment="openmotif less than 2.2.2-523"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037732" comment="openmotif-demo less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040688" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0688</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux 8.1 for IA32</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0688" source="CVE"/>
	<description>
	Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1c6cfc49def629c55e85e6a51eb19b44 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032459" comment="openmotif-devel-32bit less than 9-200410031617"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032460" comment="openmotif-devel-32bit less than 9-200410031928"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032461" comment="openmotif-devel-64bit less than 9-200410031619"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037713" comment="openmotif-devel less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
			</criteria>
		</criteria></criteria>
	<!-- 4f0e8a935331771d82d672529137b021 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037715" comment="xshared less than 4.2.0-269"/>
	</criteria>
	<!-- 5fc836c604fb00d163180bddb1be43c2 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032464" comment="XFree86-libs-32bit less than 9-200411100109"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032465" comment="XFree86-libs-32bit less than 9-200411100704"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032466" comment="XFree86-libs-64bit less than 9-200411100528"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032467" comment="XFree86-libs-x86 less than 9-200411100318"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030415" comment="XFree86-libs less than 4.3.99.902-43.35.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037716" comment="XFree86-libs less than 4.3.0-132"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030415" comment="XFree86-libs less than 4.3.99.902-43.35.3"/>
		</criteria></criteria>
	<!-- 7eda55a9d7bcfbc970fb40b2a369d418 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037717" comment="xorg-x11-devel-32bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037718" comment="xorg-x11-devel less than 6.9.0-50.45"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037717" comment="xorg-x11-devel-32bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037719" comment="xorg-x11-devel-64bit less than 6.9.0-50.45"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037718" comment="xorg-x11-devel less than 6.9.0-50.45"/>
			</criteria>
		</criteria></criteria>
	<!-- 874818c6fcf8ec787277497858d0c8f4 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037720" comment="xshared less than 4.2.0-267"/>
	</criteria>
	<!-- 99f082dd483ac0d81aa4ef9a2301d420 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032468" comment="openmotif-devel-32bit less than 9-200410081851"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032469" comment="openmotif-devel-32bit less than 9-200410082201"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032470" comment="openmotif-devel-64bit less than 9-200410082105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032471" comment="openmotif-libs-32bit less than 9-200410081851"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032472" comment="openmotif-libs-32bit less than 9-200410082201"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032473" comment="openmotif-libs-64bit less than 9-200410082105"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032474" comment="openmotif-libs less than 2.2.2-519.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
		</criteria>
	</criteria>
	<!-- b56c5555fff84ee828ea63a9bb9542f1 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032475" comment="openmotif21-libs less than 2.1.30MLI4-119.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037721" comment="openmotif21-libs less than 2.1.30MLI4-122"/>
		</criteria></criteria>
	<!-- ed9788410744ec97483978da5304464c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032476" comment="XFree86-libs-32bit less than 9-200409151952"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032477" comment="XFree86-libs-32bit less than 9-200409161634"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032478" comment="XFree86-libs-64bit less than 9-200409152030"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032479" comment="XFree86-libs-x86 less than 9-200409152035"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032480" comment="XFree86-libs less than 4.3.99.902-43.31"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037722" comment="XFree86-libs less than 4.3.0-128"/>
		</criteria></criteria>
	<!-- f9386d673ffafe49ce62f85b188b3990 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
	</criteria>
	<!-- fa8ab3ca18be2f2ad1cf95944e137087 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037723" comment="suse81 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037724" comment="openmotif-demo less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037713" comment="openmotif-devel less than 2.2.2-522"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037714" comment="openmotif less than 2.2.2-522"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037725" comment="openmotif-demo less than 2.2.2-524"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037726" comment="openmotif-devel less than 2.2.2-524"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037727" comment="openmotif less than 2.2.2-524"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037728" comment="openmotif-demo less than 2.2.2-523"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037729" comment="openmotif-devel-32bit less than 9.0-4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037730" comment="openmotif-devel less than 2.2.2-523"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037731" comment="openmotif less than 2.2.2-523"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037732" comment="openmotif-demo less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032462" comment="openmotif-devel less than 2.2.2-519.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032463" comment="openmotif less than 2.2.2-519.4"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040689" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0689</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0689" source="CVE"/>
	<description>
	KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 42f8300d963a93c070593dc30187984d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032481" comment="arts-32bit less than 9-200407271038"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032482" comment="arts-32bit less than 9-200407271118"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032483" comment="arts-64bit less than 9-200407271122"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032484" comment="arts-x86 less than 9-200407271036"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032485" comment="arts less than 1.2.1-35.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037733" comment="arts less than 1.1-143"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037734" comment="arts less than 1.0.3-220"/>
		</criteria></criteria>
	<!-- 950162438452a16c305da7fdace20716 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037735" comment="kdebase3 less than 3.1.1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037736" comment="kdelibs3 less than 3.1.1-149"/>
		</criteria>
	</criteria>
	<!-- a809b3e4737da5a6229cd188189ac882 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032486" comment="kdebase3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032487" comment="kdebase3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032488" comment="kdebase3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032489" comment="kdebase3-devel less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032490" comment="kdebase3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032491" comment="kdebase3 less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032492" comment="kdelibs3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032493" comment="kdelibs3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032494" comment="kdelibs3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032495" comment="kdelibs3-devel less than 3.2.1-44.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032496" comment="kdelibs3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032497" comment="kdelibs3 less than 3.2.1-44.28"/>
		</criteria>
	</criteria>
	<!-- d3860b7728df5f9fde0c436b3a91d5f6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037618" comment="kdelibs3-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040690" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0690</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0690" source="CVE"/>
	<description>
	The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 950162438452a16c305da7fdace20716 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037735" comment="kdebase3 less than 3.1.1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037736" comment="kdelibs3 less than 3.1.1-149"/>
		</criteria>
	</criteria>
	<!-- a809b3e4737da5a6229cd188189ac882 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032486" comment="kdebase3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032487" comment="kdebase3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032488" comment="kdebase3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032489" comment="kdebase3-devel less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032490" comment="kdebase3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032491" comment="kdebase3 less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032492" comment="kdelibs3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032493" comment="kdelibs3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032494" comment="kdelibs3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032495" comment="kdelibs3-devel less than 3.2.1-44.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032496" comment="kdelibs3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032497" comment="kdelibs3 less than 3.2.1-44.28"/>
		</criteria>
	</criteria>
	<!-- d3860b7728df5f9fde0c436b3a91d5f6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037618" comment="kdelibs3-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040691" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0691</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0691" source="CVE"/>
	<description>
	Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7160028389ea9570ffc42c1680285524 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032498" comment="qt3-32bit less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032499" comment="qt3-32bit less than 9-200408162047"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032500" comment="qt3-64bit less than 9-200408140912"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032501" comment="qt3-non-mt less than 3.3.1-41.14"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032502" comment="qt3-x86 less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032503" comment="qt3 less than 3.3.1-36.16"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037742" comment="qt3-non-mt less than 3.0.5-231"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037743" comment="qt3 less than 3.0.5-167"/>
			</criteria>
		</criteria></criteria>
	<!-- a6fd5438809ee6e74e5ae0f1f58211ea -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037744" comment="qt3 less than 3.1.1-118"/>
	</criteria>
	<!-- f2d1f8e90ce51ee8704d2a4a381d7a1f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037745" comment="qt3-static less than 3.3.1-41.14"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040692" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0692</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0692" source="CVE"/>
	<description>
	The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7160028389ea9570ffc42c1680285524 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032498" comment="qt3-32bit less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032499" comment="qt3-32bit less than 9-200408162047"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032500" comment="qt3-64bit less than 9-200408140912"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032501" comment="qt3-non-mt less than 3.3.1-41.14"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032502" comment="qt3-x86 less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032503" comment="qt3 less than 3.3.1-36.16"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037742" comment="qt3-non-mt less than 3.0.5-231"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037743" comment="qt3 less than 3.0.5-167"/>
			</criteria>
		</criteria></criteria>
	<!-- a6fd5438809ee6e74e5ae0f1f58211ea -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037744" comment="qt3 less than 3.1.1-118"/>
	</criteria>
	<!-- f2d1f8e90ce51ee8704d2a4a381d7a1f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037745" comment="qt3-static less than 3.3.1-41.14"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040693" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0693</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0693" source="CVE"/>
	<description>
	The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7160028389ea9570ffc42c1680285524 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032498" comment="qt3-32bit less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032499" comment="qt3-32bit less than 9-200408162047"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032500" comment="qt3-64bit less than 9-200408140912"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032501" comment="qt3-non-mt less than 3.3.1-41.14"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032502" comment="qt3-x86 less than 9-200408140621"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032503" comment="qt3 less than 3.3.1-36.16"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037742" comment="qt3-non-mt less than 3.0.5-231"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037743" comment="qt3 less than 3.0.5-167"/>
			</criteria>
		</criteria></criteria>
	<!-- a6fd5438809ee6e74e5ae0f1f58211ea -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037744" comment="qt3 less than 3.1.1-118"/>
	</criteria>
	<!-- f2d1f8e90ce51ee8704d2a4a381d7a1f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037745" comment="qt3-static less than 3.3.1-41.14"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040700" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0700</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0700" source="CVE"/>
	<description>
	Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
	</description>
 </metadata>
<!-- 399e6143dd24f98aa9a5a8884441c94f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032504" comment="mod_ssl less than 2.8.16-71.12"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037746" comment="mod_ssl less than 2.8.8-26"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037747" comment="mod_ssl less than 2.8.10-160"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040718" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0718</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0718" source="CVE"/>
	<description>
	The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040721" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0721</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0721" source="CVE"/>
	<description>
	Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 950162438452a16c305da7fdace20716 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037735" comment="kdebase3 less than 3.1.1-164"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037736" comment="kdelibs3 less than 3.1.1-149"/>
		</criteria>
	</criteria>
	<!-- a809b3e4737da5a6229cd188189ac882 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032486" comment="kdebase3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032487" comment="kdebase3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032488" comment="kdebase3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032489" comment="kdebase3-devel less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032490" comment="kdebase3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032491" comment="kdebase3 less than 3.2.1-68.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032492" comment="kdelibs3-32bit less than 9-200408111036"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032493" comment="kdelibs3-32bit less than 9-200408111119"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032494" comment="kdelibs3-64bit less than 9-200408111051"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032495" comment="kdelibs3-devel less than 3.2.1-44.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032496" comment="kdelibs3-x86 less than 9-200408111026"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032497" comment="kdelibs3 less than 3.2.1-44.28"/>
		</criteria>
	</criteria>
	<!-- d3860b7728df5f9fde0c436b3a91d5f6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037618" comment="kdelibs3-32bit less than 8.1-71"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037737" comment="kdebase3-devel less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037738" comment="kdebase3-konqueror less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037739" comment="kdebase3 less than 3.0.3-268"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037740" comment="kdelibs3-devel less than 3.0.3-210"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037741" comment="kdelibs3 less than 3.0.3-210"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040722" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0722</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0722" source="CVE"/>
	<description>
	Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040747" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0747</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0747" source="CVE"/>
	<description>
	Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
	</description>
 </metadata>
<!-- 4b948dfd213097ce95334628f694ce89 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032511" comment="apache2-devel less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032512" comment="apache2-doc less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032513" comment="apache2-example-pages less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032514" comment="apache2-prefork less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032515" comment="apache2-worker less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032516" comment="apache2 less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032517" comment="libapr0 less than 2.0.49-27.14"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040748" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0748</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0748" source="CVE"/>
	<description>
	mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
	</description>
 </metadata>
<!-- b5c9d8218b0d72e7090d96c19ca7c6a6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032518" comment="apache2-devel less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032519" comment="apache2-doc less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032520" comment="apache2-example-pages less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032521" comment="apache2-prefork less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032522" comment="apache2-worker less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032523" comment="apache2 less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032524" comment="libapr0 less than 2.0.49-27.11"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040749" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0749</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0749" source="CVE"/>
	<description>
	The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
	</description>
 </metadata>
<!-- f1e4c0242f65ff88f49218e6f83810a1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037756" comment="subversion-devel less than 1.0.0-73.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037757" comment="subversion-server less than 1.0.0-73.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037758" comment="subversion less than 1.0.0-73.14"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040751" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0751</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0751" source="CVE"/>
	<description>
	The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
	</description>
 </metadata>
<!-- b5c9d8218b0d72e7090d96c19ca7c6a6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032518" comment="apache2-devel less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032519" comment="apache2-doc less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032520" comment="apache2-example-pages less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032521" comment="apache2-prefork less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032522" comment="apache2-worker less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032523" comment="apache2 less than 2.0.49-27.11"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032524" comment="libapr0 less than 2.0.49-27.11"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040754" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0754</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0754" source="CVE"/>
	<description>
	Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.
	</description>
 </metadata>
<!-- 408b5a45aa6517c757ff2a3442dde745 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037759" comment="gaim less than 0.59-177"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040757" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0757</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0757" source="CVE"/>
	<description>
	Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040758" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0758</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0758" source="CVE"/>
	<description>
	Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040759" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0759</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0759" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0759" source="CVE"/>
	<description>
	Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an &lt;input type="file"&gt; tag.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040760" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0760</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0760" source="CVE"/>
	<description>
	Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040761" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0761</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0761" source="CVE"/>
	<description>
	Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040762" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0762</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0762" source="CVE"/>
	<description>
	Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040763" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0763</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0763" source="CVE"/>
	<description>
	Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040764" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0764</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0764" source="CVE"/>
	<description>
	Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040765" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0765</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0765" source="CVE"/>
	<description>
	The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2d193d1b6d19554bdd0ce86aa3f0b6d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032505" comment="mozilla-calendar less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032506" comment="mozilla-dom-inspector less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032507" comment="mozilla-irc less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032508" comment="mozilla-mail less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032509" comment="mozilla-venkman less than 1.6-74.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032510" comment="mozilla less than 1.6-74.8"/>
		</criteria>
	</criteria>
	<!-- 7e5f840fa40a27c6b0be7ddb1ebac2b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
	<!-- bf2b39a8954f9da7dd279549f39d0606 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037751" comment="mozilla-calendar less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037752" comment="mozilla-dom-inspector less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037748" comment="mozilla-irc less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037749" comment="mozilla-mail less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037753" comment="mozilla-spellchecker less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037754" comment="mozilla-venkman less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037755" comment="mozilla-xmlterm less than 1.4.1-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037750" comment="mozilla less than 1.4.1-17"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040771" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0771</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0771" source="CVE"/>
	<description>
	Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.
	</description>
 </metadata>
<!-- 7f3a31a9eb65a1e9e6f6aa767456f053 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032525" comment="lha less than 1.14i-547.10"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037760" comment="lha less than 1.14i-571"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040782" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0782</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782" source="CVE"/>
	<description>
	Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 73e4ee5080151a5b2d1d0fee0695db11 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037761" comment="gdk-pixbuf-devel less than 0.18.0-609"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
		</criteria>
	</criteria>
	<!-- 8fcf6d149f344f8517e1d3edafeb6dcb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
	</criteria>
	<!-- a88bd86017430297e8ec94b3b6fc08c0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032526" comment="gdk-pixbuf-devel less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032527" comment="gdk-pixbuf-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032528" comment="gdk-pixbuf less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032529" comment="gtk2-32bit less than 9-200409091701"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032530" comment="gtk2-32bit less than 9-200409091710"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032531" comment="gtk2-64bit less than 9-200409091646"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032532" comment="gtk2-devel less than 2.2.4-125.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032533" comment="gtk2-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032534" comment="gtk2 less than 2.2.4-125.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037763" comment="gdk-pixbuf-devel less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037765" comment="gtk2-devel less than 2.0.6-154"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037766" comment="gtk2 less than 2.0.6-154"/>
			</criteria>
		</criteria></criteria>
	<!-- c0136d5f769f780ec791f2b7c698b64b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037768" comment="gtk2-devel-64bit less than 2.8.11-0.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
			</criteria>
		</criteria></criteria>
	<!-- c612fc734c5a6fef616ae5d75a88d64a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037769" comment="gtk2 less than 2.2.1-103"/>
		</criteria>
	</criteria>
	<!-- d4c218b07f2ba5480d160398f502100d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032535" comment="gdk-pixbuf-devel less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032536" comment="gdk-pixbuf-devel less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032537" comment="gdk-pixbuf-gnome less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032538" comment="gdk-pixbuf-gnome less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032539" comment="gdk-pixbuf-x86 less than 9-200409161502"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032540" comment="gdk-pixbuf less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032541" comment="gdk-pixbuf less than 0.22.0-62.8"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040783" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0783</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783" source="CVE"/>
	<description>
	Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 73e4ee5080151a5b2d1d0fee0695db11 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037761" comment="gdk-pixbuf-devel less than 0.18.0-609"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
		</criteria>
	</criteria>
	<!-- 8fcf6d149f344f8517e1d3edafeb6dcb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
	</criteria>
	<!-- a88bd86017430297e8ec94b3b6fc08c0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032526" comment="gdk-pixbuf-devel less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032527" comment="gdk-pixbuf-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032528" comment="gdk-pixbuf less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032529" comment="gtk2-32bit less than 9-200409091701"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032530" comment="gtk2-32bit less than 9-200409091710"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032531" comment="gtk2-64bit less than 9-200409091646"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032532" comment="gtk2-devel less than 2.2.4-125.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032533" comment="gtk2-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032534" comment="gtk2 less than 2.2.4-125.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037763" comment="gdk-pixbuf-devel less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037765" comment="gtk2-devel less than 2.0.6-154"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037766" comment="gtk2 less than 2.0.6-154"/>
			</criteria>
		</criteria></criteria>
	<!-- c0136d5f769f780ec791f2b7c698b64b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037768" comment="gtk2-devel-64bit less than 2.8.11-0.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
			</criteria>
		</criteria></criteria>
	<!-- c612fc734c5a6fef616ae5d75a88d64a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037769" comment="gtk2 less than 2.2.1-103"/>
		</criteria>
	</criteria>
	<!-- d4c218b07f2ba5480d160398f502100d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032535" comment="gdk-pixbuf-devel less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032536" comment="gdk-pixbuf-devel less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032537" comment="gdk-pixbuf-gnome less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032538" comment="gdk-pixbuf-gnome less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032539" comment="gdk-pixbuf-x86 less than 9-200409161502"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032540" comment="gdk-pixbuf less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032541" comment="gdk-pixbuf less than 0.22.0-62.8"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040784" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0784</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0784" source="CVE"/>
	<description>
	The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.
	</description>
 </metadata>
<!-- 408b5a45aa6517c757ff2a3442dde745 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037759" comment="gaim less than 0.59-177"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040785" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0785</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0785" source="CVE"/>
	<description>
	Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.
	</description>
 </metadata>
<!-- 408b5a45aa6517c757ff2a3442dde745 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037759" comment="gaim less than 0.59-177"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040786" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0786</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0786" source="CVE"/>
	<description>
	The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
	</description>
 </metadata>
<!-- 4b948dfd213097ce95334628f694ce89 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032511" comment="apache2-devel less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032512" comment="apache2-doc less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032513" comment="apache2-example-pages less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032514" comment="apache2-prefork less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032515" comment="apache2-worker less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032516" comment="apache2 less than 2.0.49-27.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032517" comment="libapr0 less than 2.0.49-27.14"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040788" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0788</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0788" source="CVE"/>
	<description>
	Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 73e4ee5080151a5b2d1d0fee0695db11 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037761" comment="gdk-pixbuf-devel less than 0.18.0-609"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
		</criteria>
	</criteria>
	<!-- 8fcf6d149f344f8517e1d3edafeb6dcb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037762" comment="gdk-pixbuf less than 0.18.0-609"/>
	</criteria>
	<!-- a88bd86017430297e8ec94b3b6fc08c0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032526" comment="gdk-pixbuf-devel less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032527" comment="gdk-pixbuf-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032528" comment="gdk-pixbuf less than 0.22.0-62.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032529" comment="gtk2-32bit less than 9-200409091701"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032530" comment="gtk2-32bit less than 9-200409091710"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032531" comment="gtk2-64bit less than 9-200409091646"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032532" comment="gtk2-devel less than 2.2.4-125.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032533" comment="gtk2-x86 less than 9-200409091658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032534" comment="gtk2 less than 2.2.4-125.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037763" comment="gdk-pixbuf-devel less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037765" comment="gtk2-devel less than 2.0.6-154"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037766" comment="gtk2 less than 2.0.6-154"/>
			</criteria>
		</criteria></criteria>
	<!-- c0136d5f769f780ec791f2b7c698b64b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037768" comment="gtk2-devel-64bit less than 2.8.11-0.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037767" comment="gtk2-devel less than 2.8.11-0.15"/>
			</criteria>
		</criteria></criteria>
	<!-- c612fc734c5a6fef616ae5d75a88d64a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037764" comment="gdk-pixbuf less than 0.18.0-604"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037769" comment="gtk2 less than 2.2.1-103"/>
		</criteria>
	</criteria>
	<!-- d4c218b07f2ba5480d160398f502100d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032535" comment="gdk-pixbuf-devel less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032536" comment="gdk-pixbuf-devel less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032537" comment="gdk-pixbuf-gnome less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032538" comment="gdk-pixbuf-gnome less than 0.22.0-62.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032539" comment="gdk-pixbuf-x86 less than 9-200409161502"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032540" comment="gdk-pixbuf less than 0.22.0-62.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032541" comment="gdk-pixbuf less than 0.22.0-62.8"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040792" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0792</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Firewall on CD 2</platform>
		<platform>SuSE Firewall on CD 2 - VPN</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Office Server</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0792" source="CVE"/>
	<description>
	Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.
	</description>
 </metadata>
<!-- d1f93e35e0176de4888068920508db5c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032542" comment="rsync less than 2.6.2-8.9"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="firewall-adminhost2 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037770" comment="rsync less than 2.6.2-26"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037770" comment="rsync less than 2.6.2-26"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037771" comment="rsync less than 2.6.2-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037772" comment="rsync less than 2.6.2-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037773" comment="rsync less than 2.6.2-25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037770" comment="rsync less than 2.6.2-26"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037772" comment="rsync less than 2.6.2-24"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037772" comment="rsync less than 2.6.2-24"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037772" comment="rsync less than 2.6.2-24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037773" comment="rsync less than 2.6.2-25"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040794" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0794</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0794" source="CVE"/>
	<description>
	Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
	</description>
 </metadata>
<!-- 7df81d0a15082ec207c50ddd280d8b3a -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032543" comment="heimdal less than 0.6.1rc3-55.6"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037774" comment="heimdal less than 0.4e-405"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040796" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0796</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0796" source="CVE"/>
	<description>
	SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.
	</description>
 </metadata>
<!-- 873ec41d78d87e273acb6d24152cae23 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032544" comment="spamassassin less than 2.64-3.2"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037775" comment="spamassassin less than 2.64-4"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040801" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0801</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 10.1</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
		<platform>openSUSE 11.3</platform>
		<platform>openSUSE 11.4</platform>
	</affected>
	<reference ref_id="CVE-2004-0801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0801" source="CVE"/>
	<description>
	Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1fc35457f44c900b3d8fd5c9f5e55767 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061661" comment="suse113 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070058" comment="hplip-hpijs less than 3.10.2-2.5.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070059" comment="hplip less than 3.10.2-2.5.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066134" comment="suse114 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070060" comment="hplip-hpijs less than 3.11.5-1.5.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070061" comment="hplip less than 3.11.5-1.5.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 840abce5b365ddcc9cc77d530c39a0e4 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037777" comment="foomatic-filters less than 3.0.2-4.2"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037778" comment="suse101 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037779" comment="foomatic-filters less than 3.0.2-20.3"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037780" comment="foomatic-filters less than 3.0.2-3.2"/>
		</criteria></criteria>
	<!-- 997ad18a4f4706edd462cae443e492f0 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070056" comment="hplip-hpijs less than 3.9.8-3.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070057" comment="hplip less than 3.9.8-3.7.1"/>
		</criteria>
	</criteria>
	<!-- c5b0b422e8d7e48a178aced6fe723b75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032432" comment="cups-client less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032433" comment="cups-devel less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032434" comment="cups-libs-32bit less than 9-200408311758"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032435" comment="cups-libs-32bit less than 9-200408311952"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032436" comment="cups-libs-64bit less than 9-200408312018"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032437" comment="cups-libs-x86 less than 9-200408311747"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032438" comment="cups-libs less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032439" comment="cups less than 1.1.20-108.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032440" comment="foomatic-filters less than 3.0.1-41.6"/>
		</criteria>
	</criteria>
	<!-- f413b4212c37a07d8cb7616de4485344 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037694" comment="cups-client less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037695" comment="cups-devel less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037696" comment="cups-libs less than 1.1.15-167"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037697" comment="cups less than 1.1.15-167"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037698" comment="cups-client less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037699" comment="cups-devel less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037700" comment="cups-libs less than 1.1.15-170"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037701" comment="cups less than 1.1.15-170"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040803" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0803</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803" source="CVE"/>
	<description>
	Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b041aa0ff3776ef001f5ef9590ac9bd6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030416" comment="kdegraphics3-fax less than 3.2.1-67.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037781" comment="kdegraphics3-fax less than 3.1.1-149"/>
		</criteria></criteria>
	<!-- b96ddd23c856292e6f2d3271d511b86b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032545" comment="libtiff-32bit less than 9-200410202150"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032546" comment="libtiff-32bit less than 9-200410212027"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032547" comment="libtiff-64bit less than 9-200410210007"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032548" comment="libtiff-x86 less than 9-200410202139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032549" comment="libtiff less than 3.6.1-38.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037782" comment="libtiff less than 3.5.7-376"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040804" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0804</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804" source="CVE"/>
	<description>
	Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b041aa0ff3776ef001f5ef9590ac9bd6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030416" comment="kdegraphics3-fax less than 3.2.1-67.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037781" comment="kdegraphics3-fax less than 3.1.1-149"/>
		</criteria></criteria>
	<!-- b96ddd23c856292e6f2d3271d511b86b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032545" comment="libtiff-32bit less than 9-200410202150"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032546" comment="libtiff-32bit less than 9-200410212027"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032547" comment="libtiff-64bit less than 9-200410210007"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032548" comment="libtiff-x86 less than 9-200410202139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032549" comment="libtiff less than 3.6.1-38.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037782" comment="libtiff less than 3.5.7-376"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040805" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0805</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0805" source="CVE"/>
	<description>
	Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
	</description>
 </metadata>
<!-- 5235b6279a29e4ddc8bd0e64761aa828 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037783" comment="mpg123 less than 0.59s-490.4"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040807" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0807</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0807" source="CVE"/>
	<description>
	Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
	</description>
 </metadata>
<!-- 51640e8f4b2890b6b676c40dd61af7fd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032550" comment="samba-client less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032551" comment="samba-pdb less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032552" comment="samba-python less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032553" comment="samba-vscan less than 0.3.4-83.35"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032554" comment="samba-winbind less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032555" comment="samba less than 3.0.4-1.32"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040808" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0808</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0808" source="CVE"/>
	<description>
	The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.
	</description>
 </metadata>
<!-- 51640e8f4b2890b6b676c40dd61af7fd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032550" comment="samba-client less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032551" comment="samba-pdb less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032552" comment="samba-python less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032553" comment="samba-vscan less than 0.3.4-83.35"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032554" comment="samba-winbind less than 3.0.4-1.32"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032555" comment="samba less than 3.0.4-1.32"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040809" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0809</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0809" source="CVE"/>
	<description>
	The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 031f16f00d8a113c18c9ad3dcf15a055 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032556" comment="mod_dav less than 1.0.3-377.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037784" comment="mod_dav less than 1.0.3-382"/>
		</criteria></criteria>
	<!-- d46e1647e774463234c6b7813619514e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032557" comment="apache2-devel less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032558" comment="apache2-doc less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032559" comment="apache2-example-pages less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032560" comment="apache2-prefork less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032561" comment="apache2-worker less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032562" comment="apache2 less than 2.0.49-27.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032563" comment="libapr0 less than 2.0.49-27.16"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040814" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0814</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0814" source="CVE"/>
	<description>
	Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040815" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0815</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815" source="CVE"/>
	<description>
	The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 31b4837f99e519f020d64d49c5b1e6db -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037785" comment="samba-client less than 2.2.8a-225"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037786" comment="samba less than 2.2.8a-225"/>
		</criteria>
	</criteria>
	<!-- 520ec48d6b1bceeecaa7e6f59e6fb170 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037787" comment="samba-client less than 2.2.8a-224"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037785" comment="samba-client less than 2.2.8a-225"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037788" comment="samba-vscan less than 0.3.2a-277"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037789" comment="samba-vscan less than 0.3.2a-278"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037790" comment="samba less than 2.2.8a-224"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037786" comment="samba less than 2.2.8a-225"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037787" comment="samba-client less than 2.2.8a-224"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037788" comment="samba-vscan less than 0.3.2a-277"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037790" comment="samba less than 2.2.8a-224"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037787" comment="samba-client less than 2.2.8a-224"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037788" comment="samba-vscan less than 0.3.2a-277"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037790" comment="samba less than 2.2.8a-224"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040817" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0817</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0817" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b02e78a5845b470f64220ba1715b1792 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032577" comment="imlib-32bit less than 9-200409021137"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032578" comment="imlib-32bit less than 9-200409021330"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032579" comment="imlib-64bit less than 9-200409021135"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032580" comment="imlib-devel less than 1.9.14-180.8"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032581" comment="imlib-x86 less than 9-200409021329"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032582" comment="imlib less than 1.9.14-180.8"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037791" comment="imlib-devel less than 1.9.10-788"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037792" comment="imlib less than 1.9.10-788"/>
			</criteria>
		</criteria></criteria>
	<!-- b43341b47a187ca22f521d41859975b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037792" comment="imlib less than 1.9.10-788"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040827" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0827</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-0827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0827" source="CVE"/>
	<description>
	Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 154f4414db83882a06a0e3fa83c00520 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037793" comment="ImageMagick less than 5.5.7-225.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037794" comment="ImageMagick less than 5.4.7-273"/>
		</criteria></criteria>
	<!-- 87559c17d06f8b2f7ecf4a7d0f3cca7c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037795" comment="ImageMagick-Magick++ less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037796" comment="perl-PerlMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria></criteria>
	<!-- aee2a129487580f364fc1a28346d1467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037797" comment="ImageMagick less than 5.4.7-277"/>
	</criteria>
	<!-- cc33c157901916a8138f2ac5f98c5a24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037798" comment="ImageMagick-devel less than 5.5.7-225.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040832" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0832</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0832" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0832" source="CVE"/>
	<description>
	The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.
	</description>
 </metadata>
<!-- 20ebe5f88a2e9783292dc201bd8f61b6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032583" comment="squid less than 2.5.STABLE5-42.18"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0835</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0835" source="CVE"/>
	<description>
	MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 3a84b4e78dcc8987da4d2325fb664642 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032584" comment="mysql less than 4.0.18-32.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037800" comment="mysql less than 3.23.52-126"/>
		</criteria></criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
	<!-- ee202c526340ebd20b6cac08d230869d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030426" comment="mysql less than 4.0.18-32.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040836" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0836</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0836" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0836" source="CVE"/>
	<description>
	Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 3a84b4e78dcc8987da4d2325fb664642 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032584" comment="mysql less than 4.0.18-32.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037800" comment="mysql less than 3.23.52-126"/>
		</criteria></criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
	<!-- ee202c526340ebd20b6cac08d230869d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030426" comment="mysql less than 4.0.18-32.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040837" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0837</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0837" source="CVE"/>
	<description>
	MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 3a84b4e78dcc8987da4d2325fb664642 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032584" comment="mysql less than 4.0.18-32.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037800" comment="mysql less than 3.23.52-126"/>
		</criteria></criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
	<!-- ee202c526340ebd20b6cac08d230869d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030426" comment="mysql less than 4.0.18-32.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040883" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0883</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0883" source="CVE"/>
	<description>
	Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040884" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0884</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0884" source="CVE"/>
	<description>
	The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6f962a9de8f4c5c9ee7aea73ad1491d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037817" comment="cyrus-sasl less than 1.5.27-394"/>
	</criteria>
	<!-- 7f22d1fa5c0ced8ea65464187fdd329f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032596" comment="cyrus-sasl-32bit less than 9-200410081851"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032597" comment="cyrus-sasl-32bit less than 9-200410082201"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032598" comment="cyrus-sasl-64bit less than 9-200410082105"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032599" comment="cyrus-sasl-devel-32bit less than 9-200410081851"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032600" comment="cyrus-sasl-devel-32bit less than 9-200410082201"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032601" comment="cyrus-sasl-devel-64bit less than 9-200410082105"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032602" comment="cyrus-sasl-devel less than 2.1.18-33.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032603" comment="cyrus-sasl-x86 less than 9-200410081842"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032604" comment="cyrus-sasl less than 2.1.18-33.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037818" comment="cyrus-sasl-devel less than 1.5.27-394"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037817" comment="cyrus-sasl less than 1.5.27-394"/>
			</criteria>
		</criteria></criteria>
	<!-- a40f4ed10a27dd472508c3e4f5ccecc5 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037819" comment="cyrus-sasl2 less than 2.1.7-126"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040885" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0885</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0885" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0885" source="CVE"/>
	<description>
	The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 91ec22b46babba982fa9b8cd69030968 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032605" comment="apache2-devel less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032606" comment="apache2-doc less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032607" comment="apache2-example-pages less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032608" comment="apache2-prefork less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032609" comment="apache2-worker less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032610" comment="apache2 less than 2.0.49-27.18.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030432" comment="libapr0 less than 2.0.49-27.18.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030432" comment="libapr0 less than 2.0.49-27.18.3"/>
		</criteria></criteria>
	<!-- e2d9838c404c87687b26f66baa345567 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032611" comment="apache less than 1.3.29-71.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032612" comment="mod_ssl less than 2.8.16-71.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037820" comment="apache less than 1.3.26-163"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037821" comment="mod_ssl less than 2.8.10-163"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040886" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0886</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886" source="CVE"/>
	<description>
	Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b041aa0ff3776ef001f5ef9590ac9bd6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030416" comment="kdegraphics3-fax less than 3.2.1-67.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037781" comment="kdegraphics3-fax less than 3.1.1-149"/>
		</criteria></criteria>
	<!-- b96ddd23c856292e6f2d3271d511b86b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032545" comment="libtiff-32bit less than 9-200410202150"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032546" comment="libtiff-32bit less than 9-200410212027"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032547" comment="libtiff-64bit less than 9-200410210007"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032548" comment="libtiff-x86 less than 9-200410202139"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032549" comment="libtiff less than 3.6.1-38.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037782" comment="libtiff less than 3.5.7-376"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040888" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0888</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888" source="CVE"/>
	<description>
	Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19d6b87a34dfb2163b6961814dad275c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030433" comment="cups-client less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030434" comment="cups-devel less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032613" comment="cups-libs-32bit less than 9-200411082338"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032614" comment="cups-libs-32bit less than 9-200411090434"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032615" comment="cups-libs-64bit less than 9-200411090337"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032616" comment="cups-libs-x86 less than 9-200411082329"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030435" comment="cups-libs less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030436" comment="cups less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032617" comment="foomatic-filters less than 3.0.1-41.7"/>
		</criteria>
	</criteria>
	<!-- 449241e1570f77459eb9ce4fa0daee03 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030433" comment="cups-client less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030434" comment="cups-devel less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030435" comment="cups-libs less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030436" comment="cups less than 1.1.20-108.13"/>
		</criteria>
	</criteria>
	<!-- 5a1cbf6488e23ff3918f33b63d086b73 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037822" comment="cups-client less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037823" comment="cups-devel less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037824" comment="cups-libs less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037825" comment="cups less than 1.1.15-174"/>
		</criteria>
	</criteria>
	<!-- 7e1b8de4a98ccaee0e33a3719ab48406 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037826" comment="koffice-wordprocessing less than 1.2.1-208"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040889" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0889</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0889" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0889" source="CVE"/>
	<description>
	Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19d6b87a34dfb2163b6961814dad275c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030433" comment="cups-client less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030434" comment="cups-devel less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032613" comment="cups-libs-32bit less than 9-200411082338"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032614" comment="cups-libs-32bit less than 9-200411090434"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032615" comment="cups-libs-64bit less than 9-200411090337"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032616" comment="cups-libs-x86 less than 9-200411082329"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030435" comment="cups-libs less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030436" comment="cups less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032617" comment="foomatic-filters less than 3.0.1-41.7"/>
		</criteria>
	</criteria>
	<!-- 449241e1570f77459eb9ce4fa0daee03 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030433" comment="cups-client less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030434" comment="cups-devel less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030435" comment="cups-libs less than 1.1.20-108.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030436" comment="cups less than 1.1.20-108.13"/>
		</criteria>
	</criteria>
	<!-- 5a1cbf6488e23ff3918f33b63d086b73 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037822" comment="cups-client less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037823" comment="cups-devel less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037824" comment="cups-libs less than 1.1.15-174"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037825" comment="cups less than 1.1.15-174"/>
		</criteria>
	</criteria>
	<!-- 7e1b8de4a98ccaee0e33a3719ab48406 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037826" comment="koffice-wordprocessing less than 1.2.1-208"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040891" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0891</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0891" source="CVE"/>
	<description>
	Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
	</description>
 </metadata>
<!-- f83d87195bba0229ac4b65c0cd41c27c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037827" comment="NetworkManager-devel less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037828" comment="NetworkManager-glib less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037829" comment="NetworkManager-gnome less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037830" comment="NetworkManager-openvpn less than 0.3.2cvs20060202-20.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037831" comment="NetworkManager-vpnc less than 0.5.0cvs20060202-19.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037832" comment="NetworkManager less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037833" comment="art-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037834" comment="audit-libs-32bit less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037835" comment="audit-libs-python less than 1.2.9-12.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037836" comment="audit-libs less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037837" comment="audit less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037838" comment="beagle-evolution less than 0.2.16.3-1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037839" comment="beagle-firefox less than 0.2.16.3-1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037840" comment="beagle-gui less than 0.2.16.3-1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037841" comment="beagle less than 0.2.16.3-1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037842" comment="cifs-mount less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037843" comment="compiz less than 0.4.0-0.21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037844" comment="contact-lookup-applet less than 0.13-21.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037845" comment="dhcp-client less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037846" comment="dhcp less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037847" comment="dia less than 0.94-41.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037848" comment="evolution-devel less than 2.6.0-49.55"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037849" comment="evolution-exchange less than 2.6.0-27.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037850" comment="evolution-pilot less than 2.6.0-49.55"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037851" comment="evolution-webcal less than 2.4.1-18.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037852" comment="evolution less than 2.6.0-49.55"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037853" comment="f-spot less than 0.3.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037854" comment="gaim-devel less than 1.5.0-50.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037855" comment="gaim less than 1.5.0-50.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037856" comment="gconf-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037857" comment="gda-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037858" comment="gdb less than 6.6-12.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037859" comment="gftp less than 2.0.18-25.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037860" comment="glade-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037861" comment="glib-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037862" comment="glib2-32bit less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037863" comment="glib2-devel less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037864" comment="glib2-doc less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037865" comment="glib2 less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037866" comment="gnome-backgrounds less than 2.12.3.1-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037867" comment="gnome-filesystem less than 0.1-261.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037868" comment="gnome-games less than 2.12.3-0.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037869" comment="gnome-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037870" comment="gnomedb-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037871" comment="gnopernicus-devel less than 1.0.0-23.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037872" comment="gnopernicus less than 1.0.0-23.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037873" comment="gstreamer010-plugins-base-32bit less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037874" comment="gstreamer010-plugins-base-devel less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037875" comment="gstreamer010-plugins-base-doc less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037876" comment="gstreamer010-plugins-base-oil-32bit less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037877" comment="gstreamer010-plugins-base-oil less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037878" comment="gstreamer010-plugins-base-visual-32bit less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037879" comment="gstreamer010-plugins-base-visual less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037880" comment="gstreamer010-plugins-base less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037881" comment="gtk-sharp-32bit less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037882" comment="gtk-sharp-complete less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037883" comment="gtk-sharp-gapi less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037884" comment="gtk-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037885" comment="gtkhtml-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037886" comment="helix-dbus-server less than 0.4.0-0.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037887" comment="inkscape less than 0.43-20.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037888" comment="libbeagle-32bit less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037889" comment="libbeagle-devel less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037890" comment="libbeagle less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037891" comment="libgail-gnome-devel less than 1.1.3-41.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037892" comment="libgail-gnome less than 1.1.3-41.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037893" comment="libgdiplus less than 1.2.2-13.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037894" comment="libipoddevice-32bit less than 0.5.2-1.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037895" comment="libipoddevice less than 0.5.2-1.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037896" comment="libsmbclient-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037897" comment="libsmbclient-devel less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037898" comment="libsmbclient less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037899" comment="libtool-32bit less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037900" comment="libtool less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037901" comment="linphone-applet less than 1.2.0-16.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037902" comment="linphone less than 1.2.0-16.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037903" comment="openobex-devel less than 1.3-28.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037904" comment="openobex less than 1.3-28.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037905" comment="planner-devel less than 0.14.1-24.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037906" comment="planner less than 0.14.1-24.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037907" comment="pwlib-devel less than 1.10.4-0.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037908" comment="pwlib less than 1.10.4-0.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037909" comment="resapplet less than 0.1.4-5.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037910" comment="rsvg-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037911" comment="sabayon-admin less than 2.12.3-21.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037912" comment="sabayon less than 2.12.3-21.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037913" comment="samba-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037914" comment="samba-client-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037915" comment="samba-client less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037916" comment="samba-doc less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037917" comment="samba-krb-printing less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037918" comment="samba-pdb less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037919" comment="samba-vscan less than 0.3.6b-42.49"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037920" comment="samba-winbind-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037921" comment="samba-winbind less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037922" comment="samba less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037923" comment="tomboy less than 0.6.0-0.21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037924" comment="vte-sharp less than 1.0.10-30.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037925" comment="wbxml2 less than 0.9.0-18.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037926" comment="xgl-hardware-list less than 070326-0.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037927" comment="xgl less than cvs_060522-0.32"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10-sp1-online is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037827" comment="NetworkManager-devel less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037828" comment="NetworkManager-glib less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037829" comment="NetworkManager-gnome less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037832" comment="NetworkManager less than 0.6.4-60.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037928" comment="audit-devel less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037834" comment="audit-libs-32bit less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037929" comment="audit-libs-64bit less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037835" comment="audit-libs-python less than 1.2.9-12.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037930" comment="audit-libs-x86 less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037836" comment="audit-libs less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037837" comment="audit less than 1.2.9-6.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037842" comment="cifs-mount less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037845" comment="dhcp-client less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037931" comment="dhcp-devel less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037932" comment="dhcp-relay less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037933" comment="dhcp-server less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037846" comment="dhcp less than 3.0.3-23.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037934" comment="gdb-32bit less than 6.6-12.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037935" comment="gdb-64bit less than 6.6-12.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037936" comment="gdb-x86 less than 6.6-12.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037858" comment="gdb less than 6.6-12.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037862" comment="glib2-32bit less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037937" comment="glib2-64bit less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037863" comment="glib2-devel less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037864" comment="glib2-doc less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037938" comment="glib2-x86 less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037865" comment="glib2 less than 2.8.6-0.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037867" comment="gnome-filesystem less than 0.1-261.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037873" comment="gstreamer010-plugins-base-32bit less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037939" comment="gstreamer010-plugins-base-64bit less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037875" comment="gstreamer010-plugins-base-doc less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037940" comment="gstreamer010-plugins-base-x86 less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037880" comment="gstreamer010-plugins-base less than 0.10.5-11.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037888" comment="libbeagle-32bit less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037941" comment="libbeagle-64bit less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037942" comment="libbeagle-x86 less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037890" comment="libbeagle less than 0.2.16.3-1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037892" comment="libgail-gnome less than 1.1.3-41.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037893" comment="libgdiplus less than 1.2.2-13.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037943" comment="libmsrpc-devel less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037944" comment="libmsrpc less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037896" comment="libsmbclient-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037945" comment="libsmbclient-64bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037897" comment="libsmbclient-devel less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037946" comment="libsmbclient-x86 less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037898" comment="libsmbclient less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037899" comment="libtool-32bit less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037947" comment="libtool-64bit less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037948" comment="libtool-x86 less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037900" comment="libtool less than 1.5.22-13.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037913" comment="samba-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037949" comment="samba-64bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037914" comment="samba-client-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037950" comment="samba-client-64bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037951" comment="samba-client-x86 less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037915" comment="samba-client less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037916" comment="samba-doc less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037917" comment="samba-krb-printing less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037918" comment="samba-pdb less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037952" comment="samba-python less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037919" comment="samba-vscan less than 0.3.6b-42.49"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037920" comment="samba-winbind-32bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037953" comment="samba-winbind-64bit less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037954" comment="samba-winbind-x86 less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037921" comment="samba-winbind less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037955" comment="samba-x86 less than 3.0.24-2.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037922" comment="samba less than 3.0.24-2.23"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040902" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0902</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0902" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0902" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040903" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0903</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0903" source="CVE"/>
	<description>
	Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040904" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0904</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0904" source="CVE"/>
	<description>
	Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040905" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0905</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0905" source="CVE"/>
	<description>
	Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040906" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0906</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0906" source="CVE"/>
	<description>
	The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040908" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0908</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0908" source="CVE"/>
	<description>
	Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
	<!-- c74268c90252958dc57e3784d1d30f80 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032618" comment="mozilla-calendar less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032619" comment="mozilla-dom-inspector less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032620" comment="mozilla-irc less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032621" comment="mozilla-mail less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032622" comment="mozilla-venkman less than 1.6-74.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032623" comment="mozilla less than 1.6-74.14"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040909" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0909</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0909" source="CVE"/>
	<description>
	Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b5c195033b61691c271254a3dc3848b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037956" comment="galeon less than 1.2.13-17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037957" comment="mozilla-deat less than 1.4.1-8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037958" comment="mozilla-irc less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037959" comment="mozilla-mail less than 1.4.1-23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037960" comment="mozilla less than 1.4.1-23"/>
		</criteria>
	</criteria>
	<!-- 7c9163c638b7795bec6f012e000370ac -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037961" comment="mozilla-calendar less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037962" comment="mozilla-dom-inspector less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037963" comment="mozilla-irc less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037964" comment="mozilla-mail less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037965" comment="mozilla-spellchecker less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037966" comment="mozilla-venkman less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037967" comment="mozilla-xmlterm less than 1.4.1-21"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037968" comment="mozilla less than 1.4.1-21"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040918" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0918</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
		<platform>openSUSE 11.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0918" source="CVE"/>
	<description>
	The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7076216284149b96d6e7cf2a3c926ba5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037969" comment="suse110 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037970" comment="squid less than 2.6.STABLE20-12.1"/>
	</criteria>
	<!-- ca1d3bfa57ff6866dc44f996cd8f0472 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032624" comment="squid less than 2.5.STABLE5-42.21"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037971" comment="squid less than 2.4.STABLE7-284"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040929" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0929</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0929" source="CVE"/>
	<description>
	Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
	</description>
 </metadata>
<!-- b96ddd23c856292e6f2d3271d511b86b -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032545" comment="libtiff-32bit less than 9-200410202150"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032546" comment="libtiff-32bit less than 9-200410212027"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032547" comment="libtiff-64bit less than 9-200410210007"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032548" comment="libtiff-x86 less than 9-200410202139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032549" comment="libtiff less than 3.6.1-38.12"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037782" comment="libtiff less than 3.5.7-376"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040930" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0930</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0930" source="CVE"/>
	<description>
	The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 102b4db1a258893e865573de19d19fa8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030437" comment="samba less than 3.0.4-1.34.3"/>
	</criteria>
	<!-- f3fc34278c281e2c79bce793e847b018 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030437" comment="samba less than 3.0.4-1.34.3"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040938" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0938</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0938" source="CVE"/>
	<description>
	FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1e45eb63952773be3469e841fc17e9a7 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037972" comment="freeradius less than 0.5-414"/>
	</criteria>
	<!-- 6d94d15d144c0738548667aef4fbdcf5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032625" comment="freeradius less than 0.9.3-106.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040940" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0940</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0940" source="CVE"/>
	<description>
	Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
	</description>
 </metadata>
<!-- e2d9838c404c87687b26f66baa345567 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032611" comment="apache less than 1.3.29-71.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032612" comment="mod_ssl less than 2.8.16-71.15"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037820" comment="apache less than 1.3.26-163"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037821" comment="mod_ssl less than 2.8.10-163"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040942" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0942</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0942" source="CVE"/>
	<description>
	Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
	</description>
 </metadata>
<!-- 91ec22b46babba982fa9b8cd69030968 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032605" comment="apache2-devel less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032606" comment="apache2-doc less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032607" comment="apache2-example-pages less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032608" comment="apache2-prefork less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032609" comment="apache2-worker less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032610" comment="apache2 less than 2.0.49-27.18.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030432" comment="libapr0 less than 2.0.49-27.18.3"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030432" comment="libapr0 less than 2.0.49-27.18.3"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040947" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0947</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0947" source="CVE"/>
	<description>
	Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
	</description>
 </metadata>
<!-- a5f90882910c626aab4a025ec490d1ae -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030438" comment="unarj less than 2.65-131.6"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037973" comment="unarj less than 2.43-658"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040949" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0949</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0949" source="CVE"/>
	<description>
	The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040956" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0956</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0956" source="CVE"/>
	<description>
	MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 3a84b4e78dcc8987da4d2325fb664642 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032584" comment="mysql less than 4.0.18-32.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037800" comment="mysql less than 3.23.52-126"/>
		</criteria></criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
	<!-- ee202c526340ebd20b6cac08d230869d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030426" comment="mysql less than 4.0.18-32.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040957" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0957</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0957" source="CVE"/>
	<description>
	Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 3a84b4e78dcc8987da4d2325fb664642 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032584" comment="mysql less than 4.0.18-32.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037800" comment="mysql less than 3.23.52-126"/>
		</criteria></criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
	<!-- ee202c526340ebd20b6cac08d230869d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030426" comment="mysql less than 4.0.18-32.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040959" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0959</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0959" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0959" source="CVE"/>
	<description>
	rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.
	</description>
 </metadata>
<!-- d3e37376de7633350c988390d2ed9528 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037974" comment="mod_php4-core less than 4.2.2-481"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037975" comment="mod_php4-servlet less than 4.2.2-481"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037976" comment="mod_php4 less than 4.2.2-481"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040960" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0960</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0960" source="CVE"/>
	<description>
	FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1e45eb63952773be3469e841fc17e9a7 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037972" comment="freeradius less than 0.5-414"/>
	</criteria>
	<!-- 6d94d15d144c0738548667aef4fbdcf5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032625" comment="freeradius less than 0.9.3-106.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040961" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0961</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0961" source="CVE"/>
	<description>
	Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1e45eb63952773be3469e841fc17e9a7 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037972" comment="freeradius less than 0.5-414"/>
	</criteria>
	<!-- 6d94d15d144c0738548667aef4fbdcf5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032625" comment="freeradius less than 0.9.3-106.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040977" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0977</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0977" source="CVE"/>
	<description>
	The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
	</description>
 </metadata>
<!-- 713ad159971010743228507621c3432a -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037977" comment="postgresql-devel less than 7.2.6-2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037978" comment="postgresql-libs less than 7.2.6-2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037979" comment="postgresql-server less than 7.2.6-2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037980" comment="postgresql less than 7.2.6-2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040981" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0981</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0981" source="CVE"/>
	<description>
	Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 339ef506419b1961e4492998aff6994a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037981" comment="ImageMagick less than 5.4.7-275"/>
	</criteria>
	<!-- 87559c17d06f8b2f7ecf4a7d0f3cca7c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037795" comment="ImageMagick-Magick++ less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037796" comment="perl-PerlMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria></criteria>
	<!-- aee2a129487580f364fc1a28346d1467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037797" comment="ImageMagick less than 5.4.7-277"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040982" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0982</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0982" source="CVE"/>
	<description>
	Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.
	</description>
 </metadata>
<!-- 30dc12d515fabfa15c2ab2f29f4eb9cc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037982" comment="mpg123 less than 0.59s-490.13"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040983" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0983</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0983" source="CVE"/>
	<description>
	The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
	</description>
 </metadata>
<!-- c28d786afb20c82c552cde5011cce640 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030439" comment="ruby less than 1.8.1-42.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037983" comment="ruby less than 1.6.7-128"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040986" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0986</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0986" source="CVE"/>
	<description>
	Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5a98e6d9bc406ec2258d085933625560 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030440" comment="iptables less than 1.2.9-95.10"/>
	</criteria>
	<!-- b65afd202cc63349150e1823cfa35203 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032626" comment="iptables less than 1.2.9-95.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037984" comment="iptables less than 1.2.7a-408"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040989" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0989</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0989" source="CVE"/>
	<description>
	Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ebcaf61f6debd12131a1753d095345dd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032414" comment="libxml-32bit less than 9-200412202049"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032415" comment="libxml-32bit less than 9-200412202205"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032416" comment="libxml-64bit less than 9-200412202113"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030409" comment="libxml-devel less than 1.8.17-366.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032417" comment="libxml-x86 less than 9-200412202214"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030410" comment="libxml less than 1.8.17-366.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037552" comment="libxml-devel less than 1.8.17-370"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037553" comment="libxml-devel less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037555" comment="libxml less than 1.8.17-370"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037556" comment="libxml less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030409" comment="libxml-devel less than 1.8.17-366.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030410" comment="libxml less than 1.8.17-366.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037553" comment="libxml-devel less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037554" comment="libxml-devel less than 1.8.17-372"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037556" comment="libxml less than 1.8.17-371"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037557" comment="libxml less than 1.8.17-372"/>
			</criteria>
		</criteria></criteria>
	<!-- ffea3eaf97e43abb88f477ec4f689352 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032627" comment="libxml2-32bit less than 9-200410281810"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032628" comment="libxml2-32bit less than 9-200410291429"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032629" comment="libxml2-64bit less than 9-200410291649"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032630" comment="libxml2-devel less than 2.6.7-28.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032631" comment="libxml2-x86 less than 9-200410291421"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032632" comment="libxml2 less than 2.6.7-28.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037985" comment="libxml2-devel less than 2.4.23-241"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037986" comment="libxml2 less than 2.4.23-241"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037987" comment="libxml2-devel less than 2.4.23-240"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037988" comment="libxml2 less than 2.4.23-240"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040990" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0990</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2004-0990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990" source="CVE"/>
	<description>
	Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4779e58c1c09c726d330fd4e898b9bf7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037989" comment="gd-devel less than 2.0.32-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037990" comment="gd less than 2.0.32-7.2"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032633" comment="gd-devel less than 2.0.22-65.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032634" comment="gd less than 2.0.22-65.9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037991" comment="gd-devel less than 2.0.28-2.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037992" comment="gd less than 2.0.28-2.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037993" comment="gd-devel less than 2.0.32-6.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037994" comment="gd less than 2.0.32-6.2"/>
			</criteria>
		</criteria></criteria>
	<!-- 9dcd06f3f2cfeb4893ddff4b8c520bdf -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032633" comment="gd-devel less than 2.0.22-65.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032634" comment="gd less than 2.0.22-65.9"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040991" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0991</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-0991" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0991" source="CVE"/>
	<description>
	Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
	</description>
 </metadata>
<!-- 30dc12d515fabfa15c2ab2f29f4eb9cc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037982" comment="mpg123 less than 0.59s-490.13"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041004" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1004</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1004" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
	<!-- e702fc9f046fac6627f47fbba14635c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030441" comment="mc less than 4.6.0-324.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041005" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1005</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1005" source="CVE"/>
	<description>
	Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
	<!-- e702fc9f046fac6627f47fbba14635c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030441" comment="mc less than 4.6.0-324.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041009" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1009</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1009" source="CVE"/>
	<description>
	Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041010" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1010</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1010" source="CVE"/>
	<description>
	Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.
	</description>
 </metadata>
<!-- dfed4f3cf36d0008c8f4f5905228183c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030442" comment="zip less than 2.3-732.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037997" comment="zip less than 2.3-739"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041011" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1011</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1011" source="CVE"/>
	<description>
	Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.
	</description>
 </metadata>
<!-- f9877235fd4c7bc72534c09b2c95e19f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037998" comment="cyrus-imapd less than 2.1.16-56"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041012" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1012</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1012" source="CVE"/>
	<description>
	The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
	</description>
 </metadata>
<!-- f9877235fd4c7bc72534c09b2c95e19f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037998" comment="cyrus-imapd less than 2.1.16-56"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041013" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1013</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1013" source="CVE"/>
	<description>
	The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.
	</description>
 </metadata>
<!-- f9877235fd4c7bc72534c09b2c95e19f -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037998" comment="cyrus-imapd less than 2.1.16-56"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041014" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1014</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1014" source="CVE"/>
	<description>
	statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
	</description>
 </metadata>
<!-- 5afc6bc15a1929579e9b8c8d8c6c947e -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037999" comment="nfs-utils less than 1.0.1-168"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041016" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1016</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1016" source="CVE"/>
	<description>
	The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0dd603ae33fd9980da99a98000849da8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032635" comment="kernel-64k-pagesize less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032637" comment="kernel-sn2 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 20fe204ab30920b70619e3e473390613 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 23d93b1d08b44e20271dc04108f70d48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038000" comment="kernel-iseries64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038001" comment="kernel-ppc64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 2630a38b663386e8b39556710372cdc5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032638" comment="kernel-s390 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 46512877e6e877642d8c07a4a10b3f2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032639" comment="kernel-s390x less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 5cd50fd6b9d671d9f7353e6b811dbf2d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032640" comment="kernel-iseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032641" comment="kernel-pmac64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032642" comment="kernel-pseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 6384764803b7abea225c0fc257925adc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038003" comment="k_athlon less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038004" comment="k_deflt less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038005" comment="k_psmp less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038006" comment="k_smp less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038007" comment="kernel-source less than 2.4.19.SuSE-374"/>
		</criteria>
	</criteria>
	<!-- 664ffd54c57200e562e236f7d44dd715 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 7af6f6d1031c21dd31baae6a116e2261 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 820d43316a6ff8abd137b5f9feffa862 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038009" comment="k_itanium2-smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038010" comment="k_itanium2 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ae820d93a7554917297b834a0b797136 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038012" comment="k_numa less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ba7b20a1cb3edabd5225cf0c9bdf4450 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038013" comment="k_athlon less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038014" comment="k_debug less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038015" comment="k_psmp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- cacc34d1f090391afbadbdbceedcb110 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032643" comment="kernel-um less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032644" comment="um-host-install-initrd less than 1.0-48.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032645" comment="um-host-kernel less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041019" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1019</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1019" source="CVE"/>
	<description>
	The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 02f7ca620fa47aed580ac78750ea5c52 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032646" comment="apache-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032647" comment="apache2-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032648" comment="mod_php4-core less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032649" comment="php4-imap less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032650" comment="php4-mysql less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032651" comment="php4-session less than 4.3.4-43.22"/>
		</criteria>
	</criteria>
	<!-- 07fd95b3f9739b88441090b546febd79 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038016" comment="mod_php4-core less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038017" comment="mod_php4-devel less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038018" comment="mod_php4-servlet less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038019" comment="mod_php4 less than 4.2.2-491"/>
		</criteria>
	</criteria>
	<!-- 2e855be5ae7903ca40477ba01d9c9d02 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 7f36b0314c2e0cdee069a52ce4289795 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032666" comment="mod_php4-servlet less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 865dd631aaa5d77384d791a67fc86c6d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038020" comment="mod_php4-core less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038021" comment="mod_php4-devel less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038022" comment="mod_php4-servlet less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038023" comment="mod_php4 less than 4.2.2-489"/>
		</criteria>
	</criteria>
	<!-- 8e92be327165b504dec328c05ca4220b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032678" comment="mod_php4-servlet less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- 96d092ab1925ede50674a8e6febbc9ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 981ef108b964d6518c58b160d56e9bcc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032687" comment="mod_php4-servlet less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- b0cc027d40188c4f2c516845c31cc69f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- b5002af82ab84dcd046d50ac0c81569f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032646" comment="apache-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032647" comment="apache2-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032648" comment="mod_php4-core less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032688" comment="mod_php4-servlet less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032649" comment="php4-imap less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032650" comment="php4-mysql less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032651" comment="php4-session less than 4.3.4-43.22"/>
		</criteria>
	</criteria>
	<!-- ba2325a214aeb9526916f1f3a255babd -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038024" comment="mod_php4-core less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038025" comment="mod_php4-devel less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038026" comment="mod_php4-servlet less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038027" comment="mod_php4 less than 4.2.2-487"/>
		</criteria>
	</criteria>
	<!-- bb15f54cd03e743f9f9dd09ccc912493 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032692" comment="mod_php4-servlet less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ca818371bc02684932f162c95087c026 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038028" comment="mod_php4-core less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038029" comment="mod_php4-devel less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038030" comment="mod_php4-servlet less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038031" comment="mod_php4 less than 4.2.2-493"/>
		</criteria>
	</criteria>
	<!-- cb26dfd5c2e6259554ea496104a27638 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032700" comment="apache-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032701" comment="apache2-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032702" comment="mod_php4-core less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032703" comment="php4-imap less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032704" comment="php4-mysql less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032705" comment="php4-session less than 4.3.4-43.25"/>
		</criteria>
	</criteria>
	<!-- cc14ff30cea8ef2a4bca1724427c70e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032700" comment="apache-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032701" comment="apache2-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032702" comment="mod_php4-core less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032706" comment="mod_php4-servlet less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032703" comment="php4-imap less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032704" comment="php4-mysql less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032705" comment="php4-session less than 4.3.4-43.25"/>
		</criteria>
	</criteria>
	<!-- cc880d8594257d1c37f5c5e40549ab75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- d6325fe0853bd6af9be769dd3ffc68fc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038032" comment="mod_php4-core less than 4.2.2-485"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038033" comment="mod_php4-servlet less than 4.2.2-485"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038034" comment="mod_php4 less than 4.2.2-485"/>
		</criteria>
	</criteria>
	<!-- eb6734193188e5e67d6f06e03c942de2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
	<!-- ee8460dd87ca30f8864ad2c388d24504 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032716" comment="mod_php4-servlet less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041025" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1025</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1025" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 57d21fe8fa3815304347fcc43c6152ca -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038035" comment="imlib less than 1.9.10-791"/>
	</criteria>
	<!-- c86d1e9fa933ec51c76978e754b49b51 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032717" comment="imlib-32bit less than 9-200411221740"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032718" comment="imlib-32bit less than 9-200411221926"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032719" comment="imlib-64bit less than 9-200411221819"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030448" comment="imlib-devel less than 1.9.14-180.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032720" comment="imlib-x86 less than 9-200411221914"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030449" comment="imlib less than 1.9.14-180.11"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030448" comment="imlib-devel less than 1.9.14-180.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030449" comment="imlib less than 1.9.14-180.11"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038036" comment="imlib-devel less than 1.9.10-791"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038035" comment="imlib less than 1.9.10-791"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041026" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1026</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1026" source="CVE"/>
	<description>
	Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 57d21fe8fa3815304347fcc43c6152ca -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038035" comment="imlib less than 1.9.10-791"/>
	</criteria>
	<!-- c86d1e9fa933ec51c76978e754b49b51 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032717" comment="imlib-32bit less than 9-200411221740"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032718" comment="imlib-32bit less than 9-200411221926"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032719" comment="imlib-64bit less than 9-200411221819"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030448" comment="imlib-devel less than 1.9.14-180.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032720" comment="imlib-x86 less than 9-200411221914"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030449" comment="imlib less than 1.9.14-180.11"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030448" comment="imlib-devel less than 1.9.14-180.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030449" comment="imlib less than 1.9.14-180.11"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038036" comment="imlib-devel less than 1.9.10-791"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038035" comment="imlib less than 1.9.10-791"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041029" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1029</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1029" source="CVE"/>
	<description>
	The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20fe769b0289e11c4ae49308876a036d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038037" comment="BlackdownJava2-JRE less than 1.4.2-3"/>
	</criteria>
	<!-- 782bc79c0ff0ddb58008cb48b00673f8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030450" comment="java2-jre less than 1.4.2-129.10"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030451" comment="java2 less than 1.4.2-129.10"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038038" comment="java2-jre less than 1.4.2-140"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038039" comment="java2 less than 1.4.2-140"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038040" comment="java2-jre less than 1.3.1-687"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038041" comment="java2 less than 1.3.1-687"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041036" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1036</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1036" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.
	</description>
 </metadata>
<!-- 327ed8a0b6932e30e99ded3d5a50e811 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037677" comment="squirrelmail less than 1.4.1-241"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037678" comment="squirrelmail less than 1.4.2-55.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037679" comment="squirrelmail less than 1.4.2-59.4"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037680" comment="squirrelmail less than 1.4.2-64.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041055" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1055</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1055" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
	</description>
 </metadata>
<!-- 6d4cc744fc67bb3e24471e675c2dfcb8 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038042" comment="phpMyAdmin less than 2.4.0-77"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038043" comment="phpMyAdmin less than 2.5.3-38"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038044" comment="phpMyAdmin less than 2.5.6-34.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038045" comment="phpMyAdmin less than 2.6.0-4.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038046" comment="phpMyAdmin less than 2.6.1pl3-4.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041058" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1058</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1058" source="CVE"/>
	<description>
	Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 10563fc51e4a944b1c3b88b120fbe696 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038047" comment="k_deflt less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
	<!-- 17f9d5ebb960b52dac5a039eb35dbb4c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038049" comment="k_athlon less than 2.4.19-388"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038050" comment="k_deflt less than 2.4.19-388"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038051" comment="k_psmp less than 2.4.19-388"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038052" comment="k_smp less than 2.4.19-388"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038053" comment="kernel-source less than 2.4.19.SuSE-388"/>
		</criteria>
	</criteria>
	<!-- 53a35f9c46a14926bf6362d608669041 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038047" comment="k_deflt less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038054" comment="k_itanium2-smp less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038055" comment="k_itanium2 less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038056" comment="k_page-64k less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038057" comment="k_smp less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
	<!-- 908e2fc1ed6e9f52170be50afeb252e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038047" comment="k_deflt less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
	<!-- 90a639b6799bfd65f01fdeae93632f10 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038058" comment="kernel-iseries64 less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038059" comment="kernel-ppc64 less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
	<!-- 91e977c7e67c3b27c1652d59fa4ff24e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038047" comment="k_deflt less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038060" comment="k_numa less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038057" comment="k_smp less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
	<!-- fe38820436a873df269fdd01a2f00ece -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038061" comment="k_athlon less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038062" comment="k_debug less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038047" comment="k_deflt less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038063" comment="k_psmp less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038057" comment="k_smp less than 2.4.21-306"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038048" comment="kernel-source less than 2.4.21-306"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041062" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1062</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-1062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1062" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages.
	</description>
 </metadata>
<!-- 05fb728b909ef237a3762f0ac51dfecc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038064" comment="subversion-viewcvs less than 1.0.0-73.17"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041065" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1065</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1065" source="CVE"/>
	<description>
	Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 02f7ca620fa47aed580ac78750ea5c52 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032646" comment="apache-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032647" comment="apache2-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032648" comment="mod_php4-core less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032649" comment="php4-imap less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032650" comment="php4-mysql less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032651" comment="php4-session less than 4.3.4-43.22"/>
		</criteria>
	</criteria>
	<!-- 07fd95b3f9739b88441090b546febd79 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038016" comment="mod_php4-core less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038017" comment="mod_php4-devel less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038018" comment="mod_php4-servlet less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038019" comment="mod_php4 less than 4.2.2-491"/>
		</criteria>
	</criteria>
	<!-- 2e855be5ae7903ca40477ba01d9c9d02 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 7f36b0314c2e0cdee069a52ce4289795 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032666" comment="mod_php4-servlet less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 865dd631aaa5d77384d791a67fc86c6d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038020" comment="mod_php4-core less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038021" comment="mod_php4-devel less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038022" comment="mod_php4-servlet less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038023" comment="mod_php4 less than 4.2.2-489"/>
		</criteria>
	</criteria>
	<!-- 8e92be327165b504dec328c05ca4220b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032678" comment="mod_php4-servlet less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- 96d092ab1925ede50674a8e6febbc9ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 981ef108b964d6518c58b160d56e9bcc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032687" comment="mod_php4-servlet less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- b0cc027d40188c4f2c516845c31cc69f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- b5002af82ab84dcd046d50ac0c81569f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032646" comment="apache-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032647" comment="apache2-mod_php4 less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032648" comment="mod_php4-core less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032688" comment="mod_php4-servlet less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032649" comment="php4-imap less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032650" comment="php4-mysql less than 4.3.4-43.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032651" comment="php4-session less than 4.3.4-43.22"/>
		</criteria>
	</criteria>
	<!-- ba2325a214aeb9526916f1f3a255babd -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038024" comment="mod_php4-core less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038025" comment="mod_php4-devel less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038026" comment="mod_php4-servlet less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038027" comment="mod_php4 less than 4.2.2-487"/>
		</criteria>
	</criteria>
	<!-- bb15f54cd03e743f9f9dd09ccc912493 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032692" comment="mod_php4-servlet less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ca818371bc02684932f162c95087c026 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038028" comment="mod_php4-core less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038029" comment="mod_php4-devel less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038030" comment="mod_php4-servlet less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038031" comment="mod_php4 less than 4.2.2-493"/>
		</criteria>
	</criteria>
	<!-- cb26dfd5c2e6259554ea496104a27638 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032700" comment="apache-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032701" comment="apache2-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032702" comment="mod_php4-core less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032703" comment="php4-imap less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032704" comment="php4-mysql less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032705" comment="php4-session less than 4.3.4-43.25"/>
		</criteria>
	</criteria>
	<!-- cc14ff30cea8ef2a4bca1724427c70e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032700" comment="apache-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032701" comment="apache2-mod_php4 less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032702" comment="mod_php4-core less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032706" comment="mod_php4-servlet less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032703" comment="php4-imap less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032704" comment="php4-mysql less than 4.3.4-43.25"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032705" comment="php4-session less than 4.3.4-43.25"/>
		</criteria>
	</criteria>
	<!-- cc880d8594257d1c37f5c5e40549ab75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- d6325fe0853bd6af9be769dd3ffc68fc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038032" comment="mod_php4-core less than 4.2.2-485"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038033" comment="mod_php4-servlet less than 4.2.2-485"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038034" comment="mod_php4 less than 4.2.2-485"/>
		</criteria>
	</criteria>
	<!-- eb6734193188e5e67d6f06e03c942de2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
	<!-- ee8460dd87ca30f8864ad2c388d24504 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032716" comment="mod_php4-servlet less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041068" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1068</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1068" source="CVE"/>
	<description>
	A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0dd603ae33fd9980da99a98000849da8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032635" comment="kernel-64k-pagesize less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032637" comment="kernel-sn2 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 20fe204ab30920b70619e3e473390613 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 23d93b1d08b44e20271dc04108f70d48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038000" comment="kernel-iseries64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038001" comment="kernel-ppc64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 2630a38b663386e8b39556710372cdc5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032638" comment="kernel-s390 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 46512877e6e877642d8c07a4a10b3f2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032639" comment="kernel-s390x less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 5cd50fd6b9d671d9f7353e6b811dbf2d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032640" comment="kernel-iseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032641" comment="kernel-pmac64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032642" comment="kernel-pseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 6384764803b7abea225c0fc257925adc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038003" comment="k_athlon less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038004" comment="k_deflt less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038005" comment="k_psmp less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038006" comment="k_smp less than 2.4.19-374"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038007" comment="kernel-source less than 2.4.19.SuSE-374"/>
		</criteria>
	</criteria>
	<!-- 664ffd54c57200e562e236f7d44dd715 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 7af6f6d1031c21dd31baae6a116e2261 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 820d43316a6ff8abd137b5f9feffa862 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038009" comment="k_itanium2-smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038010" comment="k_itanium2 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ae820d93a7554917297b834a0b797136 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038012" comment="k_numa less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ba7b20a1cb3edabd5225cf0c9bdf4450 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038013" comment="k_athlon less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038014" comment="k_debug less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038015" comment="k_psmp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- cacc34d1f090391afbadbdbceedcb110 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032643" comment="kernel-um less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032644" comment="um-host-install-initrd less than 1.0-48.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032645" comment="um-host-kernel less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041070" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1070</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1070" source="CVE"/>
	<description>
	The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041071" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1071</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1071" source="CVE"/>
	<description>
	The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041072" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1072</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1072" source="CVE"/>
	<description>
	The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041073" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1073</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1073" source="CVE"/>
	<description>
	The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041074" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1074</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1074" source="CVE"/>
	<description>
	The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 16b7844739d62662da94bd667168091a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037802" comment="k_numa less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 45052d3329f87a6d395ebf1dcf0f5b95 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 473b1556343a356371498182fee359cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037805" comment="k_itanium2-smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037806" comment="k_itanium2 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 621e7c859352b22997743fc286559c71 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 813fdf370053f0b3c6c44d3451a5152e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032586" comment="kernel-um less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032587" comment="um-host-install-initrd less than 1.0-48.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032588" comment="um-host-kernel less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030427" comment="kernel-bigsmp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 8e18d7cc815e7fd96789018667b0dc56 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032589" comment="kernel-64k-pagesize less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032585" comment="kernel-debug less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032590" comment="kernel-sn2 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- 92d87faa1e5baf8482e919f3e5730961 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037807" comment="k_athlon less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037808" comment="k_deflt less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037809" comment="k_psmp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037810" comment="k_smp less than 2.4.19-370"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037811" comment="kernel-source less than 2.4.19.SuSE-370"/>
		</criteria>
	</criteria>
	<!-- 985c3bf47421fb88a4aff663f68943a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- 9dcea5669bbecc9db46285feea07a467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037812" comment="k_athlon less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037813" comment="k_debug less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037801" comment="k_deflt less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037814" comment="k_psmp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037803" comment="k_smp less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- bc6570ee193949696872f698991ed49d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030428" comment="kernel-default less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032591" comment="kernel-iseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032592" comment="kernel-pmac64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032593" comment="kernel-pseries64 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030429" comment="kernel-smp less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- bd8281abddbc1a4b203d8559bc89e01a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032594" comment="kernel-s390 less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
	<!-- e15ca505c0d4ec017a94d29bd1853da1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037815" comment="kernel-iseries64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037816" comment="kernel-ppc64 less than 2.4.21-261"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037804" comment="kernel-source less than 2.4.21-261"/>
		</criteria>
	</criteria>
	<!-- eceb314cde15f1fd4f18001c29a65a5e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032595" comment="kernel-s390x less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030430" comment="kernel-source less than 2.6.5-7.111.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030431" comment="kernel-syms less than 2.6.5-7.111.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041079" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1079</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1079" source="CVE"/>
	<description>
	Buffer overflow in (1) ncplogin and (2) ncpmap in nwclient.c for ncpfs 2.2.4, and possibly other versions, may allow local users to gain privileges via a long -T option.
	</description>
 </metadata>
<!-- 1ff6e6ba79e765dbf4515f2a5380cdd6 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032721" comment="ncpfs-devel less than 2.2.4-25.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032722" comment="ncpfs less than 2.2.4-25.4"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038065" comment="ncpfs-devel less than 2.2.0.19-140"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038066" comment="ncpfs less than 2.2.0.19-140"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041090" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1090</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1090" source="CVE"/>
	<description>
	Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041091" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1091</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1091" source="CVE"/>
	<description>
	Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041092" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1092</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1092" source="CVE"/>
	<description>
	Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041093" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1093</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1093" source="CVE"/>
	<description>
	Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041125" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1125</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125" source="CVE"/>
	<description>
	Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3ad799a3724f2f9105c795d872dba922 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032723" comment="cups-libs-32bit less than 9-200501280610"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032724" comment="cups-libs-32bit less than 9-200501281513"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032725" comment="cups-libs-64bit less than 9-200501280648"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032726" comment="cups-libs-x86 less than 9-200501280558"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038067" comment="cups-client less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038068" comment="cups-devel less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038069" comment="cups-libs less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038070" comment="cups less than 1.1.15-177"/>
			</criteria>
		</criteria></criteria>
	<!-- 477cb400d9d0b0365c64717463055b4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038071" comment="tetex less than 2.0.2-195.12"/>
	</criteria>
	<!-- 65bfa415cafadd4f47d30fbbeefc5b77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038072" comment="xpdf less than 3.00-64.32"/>
	</criteria>
	<!-- 7e1b8de4a98ccaee0e33a3719ab48406 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037826" comment="koffice-wordprocessing less than 1.2.1-208"/>
	</criteria>
	<!-- 9ff9ce097795880012e8848fc7949d1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038073" comment="xpdf-config less than 3.00-64.27"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038074" comment="xpdf less than 3.00-64.27"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041137" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1137</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1137" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1137" source="CVE"/>
	<description>
	Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0dd603ae33fd9980da99a98000849da8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032635" comment="kernel-64k-pagesize less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032637" comment="kernel-sn2 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 20fe204ab30920b70619e3e473390613 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 23d93b1d08b44e20271dc04108f70d48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038000" comment="kernel-iseries64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038001" comment="kernel-ppc64 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 2630a38b663386e8b39556710372cdc5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032638" comment="kernel-s390 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 46512877e6e877642d8c07a4a10b3f2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032639" comment="kernel-s390x less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 5cd50fd6b9d671d9f7353e6b811dbf2d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032640" comment="kernel-iseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032641" comment="kernel-pmac64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032642" comment="kernel-pseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 664ffd54c57200e562e236f7d44dd715 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 7af6f6d1031c21dd31baae6a116e2261 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- 820d43316a6ff8abd137b5f9feffa862 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038009" comment="k_itanium2-smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038010" comment="k_itanium2 less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ae820d93a7554917297b834a0b797136 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038012" comment="k_numa less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- ba7b20a1cb3edabd5225cf0c9bdf4450 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038013" comment="k_athlon less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038014" comment="k_debug less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038008" comment="k_deflt less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038015" comment="k_psmp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038011" comment="k_smp less than 2.4.21-266"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038002" comment="kernel-source less than 2.4.21-266"/>
		</criteria>
	</criteria>
	<!-- cacc34d1f090391afbadbdbceedcb110 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032643" comment="kernel-um less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032644" comment="um-host-install-initrd less than 1.0-48.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032645" comment="um-host-kernel less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041139" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1139</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139" source="CVE"/>
	<description>
	Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041140" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1140</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1140" source="CVE"/>
	<description>
	Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (application hang) and possibly fill available disk space via an invalid RTP timestamp.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041141" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1141</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141" source="CVE"/>
	<description>
	The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041142" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1142</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142" source="CVE"/>
	<description>
	Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041144" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1144</title>
	<affected family="unix">
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1144" source="CVE"/>
	<description>
	Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.
	</description>
 </metadata>
<!-- 0ffa62d48852ed6504a4ad0777ab2076 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009038077" comment="k_deflt less than 2.4.21-267"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038078" comment="k_numa less than 2.4.21-267"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038079" comment="k_smp less than 2.4.21-267"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038080" comment="kernel-source less than 2.4.21-267"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041145" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1145</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1145" source="CVE"/>
	<description>
	Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
	</description>
 </metadata>
<!-- eccaba5e191d6a572849d18ad0f149ce -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032729" comment="kdelibs3-32bit less than 9-200501242029"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032730" comment="kdelibs3-32bit less than 9-200501250047"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032731" comment="kdelibs3-64bit less than 9-200501242152"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032732" comment="kdelibs3-x86 less than 9-200501242018"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030456" comment="kdelibs3 less than 3.2.1-44.39"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038081" comment="kdelibs3-32bit less than 8.1-72"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038082" comment="kdelibs3 less than 3.0.3-212"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038083" comment="kdelibs3 less than 3.1.1-153"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030456" comment="kdelibs3 less than 3.2.1-44.39"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038082" comment="kdelibs3 less than 3.0.3-212"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041147" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1147</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1147" source="CVE"/>
	<description>
	phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
	</description>
 </metadata>
<!-- 6d4cc744fc67bb3e24471e675c2dfcb8 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038042" comment="phpMyAdmin less than 2.4.0-77"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038043" comment="phpMyAdmin less than 2.5.3-38"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038044" comment="phpMyAdmin less than 2.5.6-34.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038045" comment="phpMyAdmin less than 2.6.0-4.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038046" comment="phpMyAdmin less than 2.6.1pl3-4.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041148" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1148</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1148" source="CVE"/>
	<description>
	phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
	</description>
 </metadata>
<!-- 6d4cc744fc67bb3e24471e675c2dfcb8 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038042" comment="phpMyAdmin less than 2.4.0-77"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038043" comment="phpMyAdmin less than 2.5.3-38"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038044" comment="phpMyAdmin less than 2.5.6-34.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038045" comment="phpMyAdmin less than 2.6.0-4.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038046" comment="phpMyAdmin less than 2.6.1pl3-4.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041151" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1151</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-1151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1151" source="CVE"/>
	<description>
	Multiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local attackers to modify kernel memory and gain privileges.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0dd603ae33fd9980da99a98000849da8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032635" comment="kernel-64k-pagesize less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032637" comment="kernel-sn2 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 20fe204ab30920b70619e3e473390613 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 2630a38b663386e8b39556710372cdc5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032638" comment="kernel-s390 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 46512877e6e877642d8c07a4a10b3f2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032639" comment="kernel-s390x less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- 5cd50fd6b9d671d9f7353e6b811dbf2d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032640" comment="kernel-iseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032641" comment="kernel-pmac64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032642" comment="kernel-pseries64 less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
		</criteria>
	</criteria>
	<!-- cacc34d1f090391afbadbdbceedcb110 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032636" comment="kernel-debug less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032643" comment="kernel-um less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032644" comment="um-host-install-initrd less than 1.0-48.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032645" comment="um-host-kernel less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030443" comment="kernel-bigsmp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030444" comment="kernel-default less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030445" comment="kernel-smp less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030446" comment="kernel-source less than 2.6.5-7.111.19"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030447" comment="kernel-syms less than 2.6.5-7.111.19"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041152" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1152</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1152" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1152" source="CVE"/>
	<description>
	Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.
	</description>
 </metadata>
<!-- e77160ba6ee3d156fc8dd86250343c9c -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030457" comment="acroread less than 5.010-4.2"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038084" comment="acroread less than 5.010-5"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041154" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1154</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154" source="CVE"/>
	<description>
	Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0865bee1d4ac46f4a93ee3b8b53fa1bf -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038085" comment="samba-client less than 2.2.8a-230"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038086" comment="samba-vscan less than 0.3.2a-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038087" comment="samba less than 2.2.8a-230"/>
		</criteria>
	</criteria>
	<!-- 1bb1fd92d2c4e26305cb8bfcbdad21dd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032733" comment="libsmbclient-32bit less than 9-200412172026"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032734" comment="libsmbclient-32bit less than 9-200412172350"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032735" comment="libsmbclient-64bit less than 9-200412172257"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030458" comment="libsmbclient-devel less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030459" comment="libsmbclient less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030460" comment="samba-client less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030461" comment="samba-doc less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030462" comment="samba-pdb less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030463" comment="samba-python less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030464" comment="samba-vscan less than 0.3.5-11.7.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030465" comment="samba-winbind less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030466" comment="samba less than 3.0.9-2.1.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030458" comment="libsmbclient-devel less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030459" comment="libsmbclient less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030460" comment="samba-client less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030461" comment="samba-doc less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030462" comment="samba-pdb less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030463" comment="samba-python less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030464" comment="samba-vscan less than 0.3.5-11.7.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030465" comment="samba-winbind less than 3.0.9-2.1.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030466" comment="samba less than 3.0.9-2.1.5"/>
			</criteria>
		</criteria></criteria>
	<!-- 36f4b3cdff8f87296750a224da5e2705 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038085" comment="samba-client less than 2.2.8a-230"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038087" comment="samba less than 2.2.8a-230"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041157" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1157</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1157" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1157" source="CVE"/>
	<description>
	Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
	</description>
 </metadata>
<!-- cc6c9e7c5bdca5f99649071730a87742 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038088" comment="opera less than 8.01-4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038089" comment="opera less than 8.01-1.1"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041158" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1158</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1158" source="CVE"/>
	<description>
	Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- eccaba5e191d6a572849d18ad0f149ce -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032729" comment="kdelibs3-32bit less than 9-200501242029"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032730" comment="kdelibs3-32bit less than 9-200501250047"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032731" comment="kdelibs3-64bit less than 9-200501242152"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032732" comment="kdelibs3-x86 less than 9-200501242018"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030456" comment="kdelibs3 less than 3.2.1-44.39"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038081" comment="kdelibs3-32bit less than 8.1-72"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038082" comment="kdelibs3 less than 3.0.3-212"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038083" comment="kdelibs3 less than 3.1.1-153"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030456" comment="kdelibs3 less than 3.2.1-44.39"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038082" comment="kdelibs3 less than 3.0.3-212"/>
		</criteria></criteria>
	<!-- f8d3c9b67e958bfd5cbc688fc6ac76b6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032736" comment="kdebase3-32bit less than 9-200501242029"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032737" comment="kdebase3-32bit less than 9-200501250047"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032738" comment="kdebase3-64bit less than 9-200501242152"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032739" comment="kdebase3-x86 less than 9-200501242018"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030467" comment="kdebase3 less than 3.2.1-68.36"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038090" comment="kdebase3 less than 3.1.1-167"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030467" comment="kdebase3 less than 3.2.1-68.36"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038091" comment="kdebase3 less than 3.0.3-270"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041170" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1170</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1170" source="CVE"/>
	<description>
	a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
	</description>
 </metadata>
<!-- 74a5bf97afe2646da7a939d88a7cb1b5 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032740" comment="a2ps less than 4.13-1046.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038092" comment="a2ps less than 4.13-1048"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1174</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1174" source="CVE"/>
	<description>
	direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1175</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1175" source="CVE"/>
	<description>
	fish.c in midnight commander allows remote attackers execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1176</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1176" source="CVE"/>
	<description>
	Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1af8318e3751ba8bdbdac5793b252693 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
	</criteria>
	<!-- 707f6ab0cb10c126216da02f3d8ef766 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037996" comment="mc less than 4.5.55-762"/>
	</criteria>
	<!-- e702fc9f046fac6627f47fbba14635c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030441" comment="mc less than 4.6.0-324.10"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1177</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1177" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 02672f09967fbca5a290823e489c26af -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030468" comment="mailman less than 2.1.4-83.16.3"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030468" comment="mailman less than 2.1.4-83.16.3"/>
		</criteria></criteria>
	<!-- 1b74a5e13e60c1f476edb49b31beab57 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038093" comment="mailman less than 2.1.2-95"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030468" comment="mailman less than 2.1.4-83.16.3"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038094" comment="mailman less than 2.1.5-5.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038095" comment="mailman less than 2.1.5-16.4"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1182</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1182" source="CVE"/>
	<description>
	hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.
	</description>
 </metadata>
<!-- afab9863f2e2029aadbf6bf833f50446 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038096" comment="hylafax less than 4.1.5-210"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038097" comment="hylafax less than 4.1.3-170"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030469" comment="hylafax less than 4.1.8-24.4"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1183</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183" source="CVE"/>
	<description>
	Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 18a037c784e0b7cd1b0d6d2d678e3b55 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032741" comment="libtiff-32bit less than 9-200501041713"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032742" comment="libtiff-32bit less than 9-200501042255"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032743" comment="libtiff-64bit less than 9-200501041834"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032744" comment="libtiff-x86 less than 9-200501041705"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030470" comment="libtiff less than 3.6.1-38.14"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030470" comment="libtiff less than 3.6.1-38.14"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038098" comment="libtiff less than 3.5.7-379"/>
		</criteria></criteria>
	<!-- bb8e62a045c2aac0f526baac5a12c948 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030471" comment="tiff less than 3.6.1-38.14"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038099" comment="tiff less than 3.5.7-379"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041184" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1184</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184" source="CVE"/>
	<description>
	The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 710731c2084694b924777e34da67a64c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038100" comment="enscript less than 1.6.2-822"/>
		</criteria></criteria>
	<!-- fae313a6f767fb0e4b284149dd1ccf24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041185" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1185</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185" source="CVE"/>
	<description>
	Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 710731c2084694b924777e34da67a64c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038100" comment="enscript less than 1.6.2-822"/>
		</criteria></criteria>
	<!-- fae313a6f767fb0e4b284149dd1ccf24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041186" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1186</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186" source="CVE"/>
	<description>
	Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 710731c2084694b924777e34da67a64c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038100" comment="enscript less than 1.6.2-822"/>
		</criteria></criteria>
	<!-- fae313a6f767fb0e4b284149dd1ccf24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030472" comment="enscript less than 1.6.2-814.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041187" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1187</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1187" source="CVE"/>
	<description>
	Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
	</description>
 </metadata>
<!-- e1b7caec09d304555ca5c4dd284efd20 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038101" comment="xine-lib-32bit less than 9-200501181411"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038102" comment="xine-lib-32bit less than 9-200501181442"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038103" comment="xine-lib-64bit less than 9-200501181403"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038104" comment="xine-lib-x86 less than 9-200501181410"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041188" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1188</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1188" source="CVE"/>
	<description>
	The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
	</description>
 </metadata>
<!-- e1b7caec09d304555ca5c4dd284efd20 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038101" comment="xine-lib-32bit less than 9-200501181411"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038102" comment="xine-lib-32bit less than 9-200501181442"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038103" comment="xine-lib-64bit less than 9-200501181403"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038104" comment="xine-lib-x86 less than 9-200501181410"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041235" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1235</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235" source="CVE"/>
	<description>
	Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0dbe2e609c683ba61b4b9d9e0dab5924 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038105" comment="k_deflt less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038106" comment="kernel-source less than 2.4.21-295"/>
		</criteria>
	</criteria>
	<!-- 1019147766e9fdfa975394277aaa094f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038107" comment="kernel-iseries64 less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038108" comment="kernel-ppc64 less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
	<!-- 303377550ee97916c59afca6d7adf50f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030475" comment="kernel-default less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030476" comment="kernel-smp less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
		</criteria>
	</criteria>
	<!-- 3a05fb40f90644d48b93f5e8fb53ce03 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032745" comment="kernel-s390 less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
		</criteria>
	</criteria>
	<!-- 48bee3d4a642a4bca5d17d853d098be0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038105" comment="k_deflt less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038106" comment="kernel-source less than 2.4.21-295"/>
		</criteria>
	</criteria>
	<!-- 61e58cdb1f1faaad69c14fac628319c3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038110" comment="k_athlon less than 2.4.19-376"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038111" comment="k_deflt less than 2.4.19-376"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038112" comment="k_psmp less than 2.4.19-376"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038113" comment="k_smp less than 2.4.19-376"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038114" comment="kernel-source less than 2.4.19.SuSE-376"/>
		</criteria>
	</criteria>
	<!-- 61f709205301ab5fbcf4dea596a31ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038115" comment="k_deflt less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038116" comment="k_itanium2-smp less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038117" comment="k_itanium2 less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038118" comment="k_smp less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
	<!-- 69ddffb582a8d6e19fe711f5bd4bb472 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038105" comment="k_deflt less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038119" comment="k_numa less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038120" comment="k_smp less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038106" comment="kernel-source less than 2.4.21-295"/>
		</criteria>
	</criteria>
	<!-- 7137620a0af5426453c48a1235c34962 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032746" comment="kernel-64k-pagesize less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032747" comment="kernel-debug less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030475" comment="kernel-default less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032748" comment="kernel-sn2 less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
		</criteria>
	</criteria>
	<!-- 7cb4af3aea86af46dfe6dec778cc8168 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030475" comment="kernel-default less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032749" comment="kernel-iseries64 less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032750" comment="kernel-pmac64 less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032751" comment="kernel-pseries64 less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030476" comment="kernel-smp less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
		</criteria>
	</criteria>
	<!-- 8494b1da78e4b765909cacbb0215523a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030474" comment="kernel-bigsmp less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032747" comment="kernel-debug less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030475" comment="kernel-default less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030476" comment="kernel-smp less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032752" comment="kernel-um less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032753" comment="um-host-install-initrd less than 1.0-48.2.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032754" comment="um-host-kernel less than 2.6.5-7.111.30"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030474" comment="kernel-bigsmp less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030475" comment="kernel-default less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030476" comment="kernel-smp less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
			</criteria>
		</criteria></criteria>
	<!-- 85e05760b3103f0f201e798508c3e7cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032755" comment="kernel-s390x less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030477" comment="kernel-source less than 2.6.5-7.111.30"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030478" comment="kernel-syms less than 2.6.5-7.111.30"/>
		</criteria>
	</criteria>
	<!-- a119095a26a882ce898e6ee8dd3518c1 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038121" comment="k_athlon less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038122" comment="k_debug less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038115" comment="k_deflt less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038123" comment="k_psmp less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038118" comment="k_smp less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
	<!-- a8f15d99063c26b759b268ad1aa835a0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038115" comment="k_deflt less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
	<!-- f4566f53d19b4b4dbb97b0247614b91a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038124" comment="kernel-iseries64 less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038125" comment="kernel-ppc64 less than 2.4.21-295"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038106" comment="kernel-source less than 2.4.21-295"/>
		</criteria>
	</criteria>
	<!-- f554b86a4bb286de63150e5f2dee7be5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038115" comment="k_deflt less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038126" comment="k_numa less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038118" comment="k_smp less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
	<!-- f793cbc0ee80cc0e657b9cfb30ac8de5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038115" comment="k_deflt less than 2.4.21-273"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038109" comment="kernel-source less than 2.4.21-273"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041267" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1267</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1267" source="CVE"/>
	<description>
	Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
	</description>
 </metadata>
<!-- 3ad799a3724f2f9105c795d872dba922 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032723" comment="cups-libs-32bit less than 9-200501280610"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032724" comment="cups-libs-32bit less than 9-200501281513"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032725" comment="cups-libs-64bit less than 9-200501280648"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032726" comment="cups-libs-x86 less than 9-200501280558"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038067" comment="cups-client less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038068" comment="cups-devel less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038069" comment="cups-libs less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038070" comment="cups less than 1.1.15-177"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041268" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1268</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1268" source="CVE"/>
	<description>
	lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
	</description>
 </metadata>
<!-- 3ad799a3724f2f9105c795d872dba922 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032723" comment="cups-libs-32bit less than 9-200501280610"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032724" comment="cups-libs-32bit less than 9-200501281513"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032725" comment="cups-libs-64bit less than 9-200501280648"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032726" comment="cups-libs-x86 less than 9-200501280558"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038067" comment="cups-client less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038068" comment="cups-devel less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038069" comment="cups-libs less than 1.1.15-177"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038070" comment="cups less than 1.1.15-177"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1285</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1285" source="CVE"/>
	<description>
	Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
	</description>
 </metadata>
<!-- 0942b683eca8fe01a943affb1c97bdfa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038127" comment="MPlayer less than 0.90rc4-263"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041300" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1300</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-1300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1300" source="CVE"/>
	<description>
	Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.
	</description>
 </metadata>
<!-- e1b7caec09d304555ca5c4dd284efd20 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038101" comment="xine-lib-32bit less than 9-200501181411"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038102" comment="xine-lib-32bit less than 9-200501181442"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038103" comment="xine-lib-64bit less than 9-200501181403"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038104" comment="xine-lib-x86 less than 9-200501181410"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030473" comment="xine-lib less than 0.99.rc3a-106.18"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041304" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1304</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1304" source="CVE"/>
	<description>
	Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
	</description>
 </metadata>
<!-- 381e2bac88c1021fd101ecffeded4618 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032756" comment="file-32bit less than 9-200412071354"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032757" comment="file-32bit less than 9-200412071355"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032758" comment="file-64bit less than 9-200412071401"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032759" comment="file-x86 less than 9-200412071353"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030479" comment="file less than 4.07-48.8"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030479" comment="file less than 4.07-48.8"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038128" comment="file less than 3.37-311"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041309" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1309</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1309" source="CVE"/>
	<description>
	Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.
	</description>
 </metadata>
<!-- 0942b683eca8fe01a943affb1c97bdfa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038127" comment="MPlayer less than 0.90rc4-263"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041310" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1310</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1310" source="CVE"/>
	<description>
	Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.
	</description>
 </metadata>
<!-- 0942b683eca8fe01a943affb1c97bdfa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038127" comment="MPlayer less than 0.90rc4-263"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1311</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1311" source="CVE"/>
	<description>
	Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 0942b683eca8fe01a943affb1c97bdfa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038127" comment="MPlayer less than 0.90rc4-263"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041316" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1316</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2004-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316" source="CVE"/>
	<description>
	Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041333" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1333</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1333" source="CVE"/>
	<description>
	Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 6b993af03cbdac52472a99cfcb5d9c0b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038131" comment="k_athlon less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038132" comment="k_deflt less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038133" comment="k_psmp less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038134" comment="k_smp less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038135" comment="kernel-source less than 2.4.19.SuSE-378"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041341" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1341</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2004-1341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1341" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.
	</description>
 </metadata>
<!-- b1b71e407cf5d77f62166b35d82e82e6 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038136" comment="inf2htm less than 1.1-793"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041456" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1456</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1456" source="CVE"/>
	<description>
	filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6e344b4de4b19e04fdd63221cfda214b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038137" comment="ethereal less than 0.10.11-2.1"/>
	</criteria>
	<!-- 73eab29a6f1e506a3624095eaebb358d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032760" comment="ethereal less than 0.10.11-1.1.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038138" comment="ethereal less than 0.10.11-5"/>
		</criteria></criteria>
	<!-- c8d46a79fb9f65c633c10d6f299a78a9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038138" comment="ethereal less than 0.10.11-5"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032760" comment="ethereal less than 0.10.11-1.1.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038137" comment="ethereal less than 0.10.11-2.1"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041470" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1470</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1470" source="CVE"/>
	<description>
	CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6e344b4de4b19e04fdd63221cfda214b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038137" comment="ethereal less than 0.10.11-2.1"/>
	</criteria>
	<!-- 73eab29a6f1e506a3624095eaebb358d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032760" comment="ethereal less than 0.10.11-1.1.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038138" comment="ethereal less than 0.10.11-5"/>
		</criteria></criteria>
	<!-- c8d46a79fb9f65c633c10d6f299a78a9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038138" comment="ethereal less than 0.10.11-5"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032760" comment="ethereal less than 0.10.11-1.1.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038137" comment="ethereal less than 0.10.11-2.1"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041487" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1487</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1487" source="CVE"/>
	<description>
	wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
	</description>
 </metadata>
<!-- 69ab05af8c65eb68c88d3dcfdde7ce33 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030480" comment="wget less than 1.9.1-45.10.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038139" comment="wget less than 1.8.2-363"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041488" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1488</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 10.1</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1488" source="CVE"/>
	<description>
	wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3074d571767e5876519907c7bbef2950 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038140" comment="wget less than 1.10.1-2.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037778" comment="suse101 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038141" comment="wget less than 1.10.2-15.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030481" comment="wget less than 1.9.1-45.16"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038142" comment="wget less than 1.10-1.5"/>
		</criteria></criteria>
	<!-- e7b01249711fe56bb3b36a58d161aeea -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030481" comment="wget less than 1.9.1-45.16"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030481" comment="wget less than 1.9.1-45.16"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038143" comment="wget less than 1.8.2-365"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041725" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1725</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1725" source="CVE"/>
	<description>
	Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 43b2efb78bbe436ccffb6340ffdaa616 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
	</criteria>
	<!-- 4e0ef0b05402f48b97d810e9f5177759 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038145" comment="xv less than 3.10a-1076"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038146" comment="xv less than 3.10a-1062.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038147" comment="xv less than 3.10a-1069.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041726" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1726</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2004-1726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1726" source="CVE"/>
	<description>
	Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 43b2efb78bbe436ccffb6340ffdaa616 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
	</criteria>
	<!-- 4e0ef0b05402f48b97d810e9f5177759 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038145" comment="xv less than 3.10a-1076"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038146" comment="xv less than 3.10a-1062.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038147" comment="xv less than 3.10a-1069.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041772" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-1772</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 7 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-1772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1772" source="CVE"/>
	<description>
	Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- c017779e535f590b8aa70d49948724f6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030482" comment="sharutils less than 4.2c-710.10"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038148" comment="sharutils less than 4.2c-727"/>
		</criteria></criteria>
	<!-- c874692cb34ef0e232d99615e0108852 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036728" comment="sles7 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038149" comment="sharutils less than 4.2c-718"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038149" comment="sharutils less than 4.2c-718"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20042154" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-2154</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-2154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2154" source="CVE"/>
	<description>
	CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
	</description>
 </metadata>
<!-- 9075c3f9926c17c38fa9987a9765a580 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009038150" comment="cups-client less than 1.1.15-179"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038151" comment="cups-devel less than 1.1.15-179"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038152" comment="cups-libs less than 1.1.15-179"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038153" comment="cups less than 1.1.15-179"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20042652" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-2652</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-2652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2652" source="CVE"/>
	<description>
	The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
	</description>
 </metadata>
<!-- 5089e6d3510ca8b78864f8a2a44eb7da -->
<criteria operator="OR">
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030483" comment="snort less than 2.3.2-0.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038154" comment="snort less than 2.3.2-7"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20042655" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-2655</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-2655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2655" source="CVE"/>
	<description>
	rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.
	</description>
 </metadata>
<!-- 6ab8000970d5ad02e9cb807b3fab486e -->
<criteria operator="OR">
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032761" comment="xscreensaver less than 4.16-2.24"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038155" comment="xscreensaver less than 4.05-339"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20042658" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-2658</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2004-2658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2658" source="CVE"/>
	<description>
	resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.
	</description>
 </metadata>
<!-- fa6c6a3e792bf79b1d85821c689ea578 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032762" comment="resmgr-32bit less than 9-200410202150"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032763" comment="resmgr-32bit less than 9-200410212027"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032764" comment="resmgr-64bit less than 9-200410210007"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032765" comment="resmgr-x86 less than 9-200410202139"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032766" comment="resmgr less than 0.9.8-47.6"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038156" comment="resmgr less than 0.9.7-166"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20042680" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-2680</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SLE SDK 10 SP1 for IBM iSeries and IBM pSeries</platform>
		<platform>SLE SDK 10 SP1 for IBM zSeries</platform>
		<platform>SLE SDK 10 SP1 for IPF</platform>
		<platform>SLE SDK 10 SP1 for X86-64</platform>
		<platform>SLE SDK 10 SP1 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 10.1</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
	</affected>
	<reference ref_id="CVE-2004-2680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2680" source="CVE"/>
	<description>
	mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8e18868e044b30c59445fbd838a3f071 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038157" comment="apache2-mod_python less than 3.1.3-43.3"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037778" comment="suse101 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038158" comment="apache2-mod_python less than 3.1.3-60.9"/>
		</criteria></criteria>
	<!-- ae83e0f8a577fb44058210a131c1707f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032767" comment="apache2-mod_python less than 3.1.3-37.9"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036679" comment="sles10 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038158" comment="apache2-mod_python less than 3.1.3-60.9"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050003" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0003</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0003" source="CVE"/>
	<description>
	The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
	</description>
 </metadata>
<!-- 6b993af03cbdac52472a99cfcb5d9c0b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009038131" comment="k_athlon less than 2.4.19-378"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038132" comment="k_deflt less than 2.4.19-378"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038133" comment="k_psmp less than 2.4.19-378"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038134" comment="k_smp less than 2.4.19-378"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038135" comment="kernel-source less than 2.4.19.SuSE-378"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050005" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0005</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2005-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005" source="CVE"/>
	<description>
	Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 87559c17d06f8b2f7ecf4a7d0f3cca7c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037795" comment="ImageMagick-Magick++ less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030422" comment="ImageMagick-devel less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030423" comment="ImageMagick less than 5.5.7-225.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037796" comment="perl-PerlMagick less than 5.5.7-225.12"/>
			</criteria>
		</criteria></criteria>
	<!-- aee2a129487580f364fc1a28346d1467 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037797" comment="ImageMagick less than 5.4.7-277"/>
	</criteria>
	<!-- c63e20288ce2b23db9e99040524a1226 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10-sp1-online is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038159" comment="perl-PerlMagick less than 6.2.5-16.20"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050006" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0006</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0006" source="CVE"/>
	<description>
	The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050007" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0007</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007" source="CVE"/>
	<description>
	Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050008" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0008</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0008" source="CVE"/>
	<description>
	Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause "memory corruption."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050009" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0009</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0009" source="CVE"/>
	<description>
	Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050010" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0010</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010" source="CVE"/>
	<description>
	Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050013" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0013</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0013" source="CVE"/>
	<description>
	nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
	</description>
 </metadata>
<!-- 011af757e120a14a2fae7dc271470bac -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032768" comment="ncpfs-devel less than 2.2.4-25.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030484" comment="ncpfs less than 2.2.4-25.7"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030484" comment="ncpfs less than 2.2.4-25.7"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038160" comment="ncpfs-devel less than 2.2.0.19-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038161" comment="ncpfs less than 2.2.0.19-143"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050014" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0014</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0014" source="CVE"/>
	<description>
	Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
	</description>
 </metadata>
<!-- 011af757e120a14a2fae7dc271470bac -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032768" comment="ncpfs-devel less than 2.2.4-25.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030484" comment="ncpfs less than 2.2.4-25.7"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030484" comment="ncpfs less than 2.2.4-25.7"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038160" comment="ncpfs-devel less than 2.2.0.19-143"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038161" comment="ncpfs less than 2.2.0.19-143"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050064" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0064</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0064" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064" source="CVE"/>
	<description>
	Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3ad799a3724f2f9105c795d872dba922 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032723" comment="cups-libs-32bit less than 9-200501280610"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032724" comment="cups-libs-32bit less than 9-200501281513"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032725" comment="cups-libs-64bit less than 9-200501280648"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032726" comment="cups-libs-x86 less than 9-200501280558"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030452" comment="cups-client less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030453" comment="cups-devel less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030454" comment="cups-libs less than 1.1.20-108.22"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030455" comment="cups less than 1.1.20-108.22"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038067" comment="cups-client less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038068" comment="cups-devel less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038069" comment="cups-libs less than 1.1.15-177"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038070" comment="cups less than 1.1.15-177"/>
			</criteria>
		</criteria></criteria>
	<!-- 65bfa415cafadd4f47d30fbbeefc5b77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038072" comment="xpdf less than 3.00-64.32"/>
	</criteria>
	<!-- 7e1b8de4a98ccaee0e33a3719ab48406 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037826" comment="koffice-wordprocessing less than 1.2.1-208"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0077</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2005-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0077" source="CVE"/>
	<description>
	The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
	</description>
 </metadata>
<!-- 8aa98d5798533419fb0a3680753d016e -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030485" comment="perl-DBI less than 1.41-28.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038162" comment="perl-DBI less than 1.28-119"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0084</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084" source="CVE"/>
	<description>
	Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04002f442555d12065ebb4ba411fe086 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
		</criteria></criteria>
	<!-- 3da7cd4d6bee83b91d40d60bcad8671f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032728" comment="ethereal less than 0.10.3-15.12"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038076" comment="ethereal less than 0.10.3-28"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0085</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0085" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bef9960cd7fc1e9abf9c974b61553b05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038163" comment="htdig less than 3.1.6-407"/>
	</criteria>
	<!-- fa6460ee9d0f0d2825a93384290f3be6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030486" comment="htdig less than 3.1.6-402.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038163" comment="htdig less than 3.1.6-407"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050088" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0088</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0088" source="CVE"/>
	<description>
	The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bc46d14c9c70aa91a3d9b309a88daf9f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032769" comment="mod_python less than 2.7.10-83.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038164" comment="mod_python less than 2.7.10-89"/>
		</criteria></criteria>
	<!-- e96984925053acf010b1e884fbc4ab43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032770" comment="apache2-mod_python less than 3.1.3-37.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050089" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0089</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0089" source="CVE"/>
	<description>
	The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.
	</description>
 </metadata>
<!-- 5eeac52472f698f9b7d58fdd1ad968ce -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032771" comment="python-32bit less than 9-200502051955"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032772" comment="python-32bit less than 9-200502060348"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032773" comment="python-64bit less than 9-200502060420"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032774" comment="python-x86 less than 9-200502051945"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030487" comment="python less than 2.3.3-88.9"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030487" comment="python less than 2.3.3-88.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038165" comment="python less than 2.2.1-188"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0094</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094" source="CVE"/>
	<description>
	Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
	</description>
 </metadata>
<!-- 69dddd7a74293a6e4941544ef2bd4761 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032775" comment="squid less than 2.5.STABLE5-42.24"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038166" comment="squid less than 2.4.STABLE7-288"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0095</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0095" source="CVE"/>
	<description>
	The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.
	</description>
 </metadata>
<!-- 69dddd7a74293a6e4941544ef2bd4761 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032775" comment="squid less than 2.5.STABLE5-42.24"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038166" comment="squid less than 2.4.STABLE7-288"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050096" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0096</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0096" source="CVE"/>
	<description>
	Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).
	</description>
 </metadata>
<!-- 69dddd7a74293a6e4941544ef2bd4761 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032775" comment="squid less than 2.5.STABLE5-42.24"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038166" comment="squid less than 2.4.STABLE7-288"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0097</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097" source="CVE"/>
	<description>
	The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.
	</description>
 </metadata>
<!-- 69dddd7a74293a6e4941544ef2bd4761 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032775" comment="squid less than 2.5.STABLE5-42.24"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038166" comment="squid less than 2.4.STABLE7-288"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050102" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0102</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0102" source="CVE"/>
	<description>
	Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6fdd96c90662a5947afc96f9d312b314 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038167" comment="evolution less than 1.2.3-161"/>
	</criteria>
	<!-- fb4269ad84693e505fb2ee19888151ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030488" comment="evolution-pilot less than 2.0.1-1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030489" comment="evolution less than 2.0.1-1.5"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050103" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0103</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0103" source="CVE"/>
	<description>
	PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.
	</description>
 </metadata>
<!-- 327ed8a0b6932e30e99ded3d5a50e811 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037677" comment="squirrelmail less than 1.4.1-241"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037678" comment="squirrelmail less than 1.4.2-55.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037679" comment="squirrelmail less than 1.4.2-59.4"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037680" comment="squirrelmail less than 1.4.2-64.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050104" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0104</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0104" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.
	</description>
 </metadata>
<!-- 327ed8a0b6932e30e99ded3d5a50e811 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037677" comment="squirrelmail less than 1.4.1-241"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037678" comment="squirrelmail less than 1.4.2-55.6"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037679" comment="squirrelmail less than 1.4.2-59.4"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037680" comment="squirrelmail less than 1.4.2-64.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050135" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0135</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
	</affected>
	<reference ref_id="CVE-2005-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0135" source="CVE"/>
	<description>
	The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050136" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0136</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0136" source="CVE"/>
	<description>
	The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 2f052099ef01089eb6b25acc317b9dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038168" comment="kernel-iseries64 less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038169" comment="kernel-ppc64 less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038170" comment="kernel-source less than 2.4.21-281"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 8f73318e0a10f5c831d299a931da12af -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038171" comment="k_deflt less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038172" comment="k_numa less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038173" comment="k_smp less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038170" comment="kernel-source less than 2.4.21-281"/>
		</criteria>
	</criteria>
	<!-- a61339581b6051bfb9c0b68c458d5930 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038174" comment="k_deflt less than 2.4.21-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038175" comment="k_itanium2-smp less than 2.4.21-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038176" comment="k_itanium2 less than 2.4.21-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038177" comment="k_page-64k less than 2.4.21-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038178" comment="k_smp less than 2.4.21-283"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038179" comment="kernel-source less than 2.4.21-283"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- c643da5f2818ac7452d602b15588f117 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038180" comment="k_athlon less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038181" comment="k_debug less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038171" comment="k_deflt less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038182" comment="k_psmp less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038173" comment="k_smp less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038170" comment="kernel-source less than 2.4.21-281"/>
		</criteria>
	</criteria>
	<!-- cedc44707f84bf949d45f8efab404b0b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038171" comment="k_deflt less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038170" comment="kernel-source less than 2.4.21-281"/>
		</criteria>
	</criteria>
	<!-- d3661da3f395c6d0b3932c0dce8c3c28 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038171" comment="k_deflt less than 2.4.21-281"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038170" comment="kernel-source less than 2.4.21-281"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050141" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0141</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0141" source="CVE"/>
	<description>
	Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
	</description>
 </metadata>
<!-- c8714c9c87fbfbe9ef59302860f58032 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009038183" comment="galeon less than 1.2.13-19"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038184" comment="mozilla-deat less than 1.4.1-10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038185" comment="mozilla-irc less than 1.4.1-30"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038186" comment="mozilla-mail less than 1.4.1-30"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038187" comment="mozilla less than 1.4.1-30"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050142" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0142</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142" source="CVE"/>
	<description>
	Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050144" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0144</title>
	<affected family="unix">
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144" source="CVE"/>
	<description>
	Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
	</description>
 </metadata>
<!-- c8714c9c87fbfbe9ef59302860f58032 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009038183" comment="galeon less than 1.2.13-19"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038184" comment="mozilla-deat less than 1.4.1-10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038185" comment="mozilla-irc less than 1.4.1-30"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038186" comment="mozilla-mail less than 1.4.1-30"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038187" comment="mozilla less than 1.4.1-30"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050149" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0149</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149" source="CVE"/>
	<description>
	Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050155" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0155</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0155" source="CVE"/>
	<description>
	The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.
	</description>
 </metadata>
<!-- 7e6cf48cf7a796f79176269c2c18b8df -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032418" comment="perl-32bit less than 9-200502051955"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032419" comment="perl-32bit less than 9-200502060348"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032420" comment="perl-64bit less than 9-200502060420"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032421" comment="perl-x86 less than 9-200502051945"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037637" comment="perl less than 5.8.0-201"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050156" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0156</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0156" source="CVE"/>
	<description>
	Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
	</description>
 </metadata>
<!-- 7e6cf48cf7a796f79176269c2c18b8df -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032418" comment="perl-32bit less than 9-200502051955"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032419" comment="perl-32bit less than 9-200502060348"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032420" comment="perl-64bit less than 9-200502060420"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032421" comment="perl-x86 less than 9-200502051945"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030411" comment="perl less than 5.8.3-32.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037637" comment="perl less than 5.8.0-201"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050160" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0160</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0160" source="CVE"/>
	<description>
	Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a57bec2ad73500fd2a5526eca6b9e9f4 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030490" comment="unace less than 1.2b-621.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038188" comment="unace less than 1.2b-647"/>
		</criteria></criteria>
	<!-- adcd15df4dccafcbe31c8148099565fc -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038188" comment="unace less than 1.2b-647"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030490" comment="unace less than 1.2b-621.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038189" comment="unace less than 1.2b-642.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038190" comment="unace less than 2.5-134.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038191" comment="unace less than 1.2b-643.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038192" comment="unace less than 2.5-135.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050161" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0161</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0161" source="CVE"/>
	<description>
	Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a57bec2ad73500fd2a5526eca6b9e9f4 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030490" comment="unace less than 1.2b-621.4"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038188" comment="unace less than 1.2b-647"/>
		</criteria></criteria>
	<!-- adcd15df4dccafcbe31c8148099565fc -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038188" comment="unace less than 1.2b-647"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030490" comment="unace less than 1.2b-621.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038189" comment="unace less than 1.2b-642.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038190" comment="unace less than 2.5-134.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038191" comment="unace less than 1.2b-643.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038192" comment="unace less than 2.5-135.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0177</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0177" source="CVE"/>
	<description>
	nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.
	</description>
 </metadata>
<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0179</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0179" source="CVE"/>
	<description>
	Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.
	</description>
 </metadata>
<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050198" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0198</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0198" source="CVE"/>
	<description>
	A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
	</description>
 </metadata>
<!-- ec6cc69bcd2bac2e8285ff85b1027168 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032776" comment="imap less than 2002e-92.4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038193" comment="imap less than 2001a-243"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050202" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0202</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0202" source="CVE"/>
	<description>
	Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 98f5b90c27d1ba5c76b51671dbbdb8bf -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030491" comment="mailman less than 2.1.4-83.13"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038194" comment="mailman less than 2.0.14-23"/>
		</criteria></criteria>
	<!-- f55591f9a204677ce573ccf38ce9c0c1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030492" comment="mailman less than 2.1.4-83.14"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050208" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0208</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0208" source="CVE"/>
	<description>
	The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0209</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0209" source="CVE"/>
	<description>
	Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050210" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0210</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0210" source="CVE"/>
	<description>
	Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0211</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211" source="CVE"/>
	<description>
	Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.
	</description>
 </metadata>
<!-- 2121acad3e298802edbe172432353179 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032777" comment="squid less than 2.5.STABLE5-42.27"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038200" comment="squid less than 2.4.STABLE7-290"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050227" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0227</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0227" source="CVE"/>
	<description>
	PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 305407891b82a33f0b970b733fab4d70 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038201" comment="postgresql-devel less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038202" comment="postgresql-jdbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038203" comment="postgresql-libs less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038204" comment="postgresql-odbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038205" comment="postgresql-perl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038206" comment="postgresql-python less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038207" comment="postgresql-server less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038208" comment="postgresql-tcl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038209" comment="postgresql less than 7.2.7-4"/>
		</criteria>
	</criteria>
	<!-- 631a12347810e4a9ff7c3bbaafbccd39 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038210" comment="postgresql-libs-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038211" comment="postgresql-contrib less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038212" comment="postgresql-devel less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038213" comment="postgresql-docs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038214" comment="postgresql-libs-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038215" comment="postgresql-libs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038216" comment="postgresql-pl less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038217" comment="postgresql-server less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038218" comment="postgresql less than 7.4.7-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038219" comment="postgresql-contrib less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038220" comment="postgresql-devel less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038221" comment="postgresql-docs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038222" comment="postgresql-libs-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038223" comment="postgresql-libs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038224" comment="postgresql-pl less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038225" comment="postgresql-server less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038226" comment="postgresql less than 8.0.1-6"/>
			</criteria>
		</criteria></criteria>
	<!-- 69187db2b25d279a07fa77241b629f8a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038227" comment="postgresql-devel less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038228" comment="postgresql-jdbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038229" comment="postgresql-libs less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038230" comment="postgresql-odbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038231" comment="postgresql-perl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038232" comment="postgresql-python less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038233" comment="postgresql-server less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038234" comment="postgresql-tcl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038235" comment="postgresql less than 7.2.8-2"/>
		</criteria>
	</criteria>
	<!-- 8522a86bfa9ca66f0b82fb3eb0042bae -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032778" comment="postgresql-libs-32bit less than 9-200506061933"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032779" comment="postgresql-libs-32bit less than 9-200506062151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032780" comment="postgresql-libs-64bit less than 9-200506062057"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032781" comment="postgresql-libs-x86 less than 9-200506061918"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria></criteria>
	<!-- c881b0eb54c9c29c35b7efe0a21e8e89 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038236" comment="postgresql-libs-32bit less than 9.1-200506061950"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038237" comment="postgresql-contrib less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038238" comment="postgresql-devel less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038239" comment="postgresql-docs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038240" comment="postgresql-libs-32bit less than 9.2-200506062019"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038241" comment="postgresql-libs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038242" comment="postgresql-pl less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038243" comment="postgresql-server less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038244" comment="postgresql less than 7.4.8-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038245" comment="postgresql-contrib less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038246" comment="postgresql-devel less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038247" comment="postgresql-docs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038248" comment="postgresql-libs-32bit less than 9.3-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038249" comment="postgresql-libs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038250" comment="postgresql-pl less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038251" comment="postgresql-server less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038252" comment="postgresql less than 8.0.3-1.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e782a2a7e7df8fe7a4f54f1fa8172438 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032782" comment="postgresql-libs-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032783" comment="postgresql-libs-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032784" comment="postgresql-libs-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032785" comment="postgresql-libs-x86 less than 9-200504131636"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria></criteria>
	<!-- f1b45b741bf9a13090640cc43f58ee08 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038253" comment="postgresql-devel less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038254" comment="postgresql-jdbc less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038255" comment="postgresql-libs less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038256" comment="postgresql-odbc less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038257" comment="postgresql-perl less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038258" comment="postgresql-python less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038259" comment="postgresql-server less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038260" comment="postgresql-tcl less than 7.2.7-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038261" comment="postgresql less than 7.2.7-2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050230" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0230</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0230" source="CVE"/>
	<description>
	Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050231" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0231</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
	</affected>
	<reference ref_id="CVE-2005-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0231" source="CVE"/>
	<description>
	Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."
	</description>
 </metadata>
<!-- a51f0a3982f40ddfe509b210b6288bd7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030508" comment="MozillaFirefox-translations less than 1.0.1-9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030509" comment="MozillaFirefox less than 1.0.1-9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050232" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0232</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
	</affected>
	<reference ref_id="CVE-2005-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0232" source="CVE"/>
	<description>
	Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."
	</description>
 </metadata>
<!-- a51f0a3982f40ddfe509b210b6288bd7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030508" comment="MozillaFirefox-translations less than 1.0.1-9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030509" comment="MozillaFirefox less than 1.0.1-9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050233" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0233</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233" source="CVE"/>
	<description>
	The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a51f0a3982f40ddfe509b210b6288bd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030508" comment="MozillaFirefox-translations less than 1.0.1-9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030509" comment="MozillaFirefox less than 1.0.1-9.1"/>
		</criteria>
	</criteria>
	<!-- e20e43dabc72bffe909f8ae39f4732d8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038262" comment="mozilla-deat less than 1.7.6-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038263" comment="mozilla-irc less than 1.7.8-19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038264" comment="mozilla-mail less than 1.7.8-19"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038265" comment="mozilla less than 1.7.8-19"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050235" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0235</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0235" source="CVE"/>
	<description>
	The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
	</description>
 </metadata>
<!-- 4adf474a02d6a4cb71cf4ed16709b8c4 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038266" comment="opera less than 8.0-4"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038267" comment="opera less than 8.0-1.1"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050241" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0241</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241" source="CVE"/>
	<description>
	The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2121acad3e298802edbe172432353179 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032777" comment="squid less than 2.5.STABLE5-42.27"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038200" comment="squid less than 2.4.STABLE7-290"/>
		</criteria></criteria>
	<!-- 46d04b64d752063540e49f5a56c6f3c3 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032786" comment="squid less than 2.5.STABLE5-42.30"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038268" comment="squid less than 2.4.STABLE7-293"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050244" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0244</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0244" source="CVE"/>
	<description>
	PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 305407891b82a33f0b970b733fab4d70 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038201" comment="postgresql-devel less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038202" comment="postgresql-jdbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038203" comment="postgresql-libs less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038204" comment="postgresql-odbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038205" comment="postgresql-perl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038206" comment="postgresql-python less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038207" comment="postgresql-server less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038208" comment="postgresql-tcl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038209" comment="postgresql less than 7.2.7-4"/>
		</criteria>
	</criteria>
	<!-- 631a12347810e4a9ff7c3bbaafbccd39 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038210" comment="postgresql-libs-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038211" comment="postgresql-contrib less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038212" comment="postgresql-devel less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038213" comment="postgresql-docs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038214" comment="postgresql-libs-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038215" comment="postgresql-libs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038216" comment="postgresql-pl less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038217" comment="postgresql-server less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038218" comment="postgresql less than 7.4.7-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038219" comment="postgresql-contrib less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038220" comment="postgresql-devel less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038221" comment="postgresql-docs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038222" comment="postgresql-libs-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038223" comment="postgresql-libs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038224" comment="postgresql-pl less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038225" comment="postgresql-server less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038226" comment="postgresql less than 8.0.1-6"/>
			</criteria>
		</criteria></criteria>
	<!-- 69187db2b25d279a07fa77241b629f8a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038227" comment="postgresql-devel less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038228" comment="postgresql-jdbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038229" comment="postgresql-libs less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038230" comment="postgresql-odbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038231" comment="postgresql-perl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038232" comment="postgresql-python less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038233" comment="postgresql-server less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038234" comment="postgresql-tcl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038235" comment="postgresql less than 7.2.8-2"/>
		</criteria>
	</criteria>
	<!-- 8522a86bfa9ca66f0b82fb3eb0042bae -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032778" comment="postgresql-libs-32bit less than 9-200506061933"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032779" comment="postgresql-libs-32bit less than 9-200506062151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032780" comment="postgresql-libs-64bit less than 9-200506062057"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032781" comment="postgresql-libs-x86 less than 9-200506061918"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria></criteria>
	<!-- c881b0eb54c9c29c35b7efe0a21e8e89 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038236" comment="postgresql-libs-32bit less than 9.1-200506061950"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038237" comment="postgresql-contrib less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038238" comment="postgresql-devel less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038239" comment="postgresql-docs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038240" comment="postgresql-libs-32bit less than 9.2-200506062019"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038241" comment="postgresql-libs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038242" comment="postgresql-pl less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038243" comment="postgresql-server less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038244" comment="postgresql less than 7.4.8-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038245" comment="postgresql-contrib less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038246" comment="postgresql-devel less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038247" comment="postgresql-docs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038248" comment="postgresql-libs-32bit less than 9.3-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038249" comment="postgresql-libs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038250" comment="postgresql-pl less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038251" comment="postgresql-server less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038252" comment="postgresql less than 8.0.3-1.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e782a2a7e7df8fe7a4f54f1fa8172438 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032782" comment="postgresql-libs-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032783" comment="postgresql-libs-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032784" comment="postgresql-libs-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032785" comment="postgresql-libs-x86 less than 9-200504131636"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050245" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0245</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0245" source="CVE"/>
	<description>
	Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 305407891b82a33f0b970b733fab4d70 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038201" comment="postgresql-devel less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038202" comment="postgresql-jdbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038203" comment="postgresql-libs less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038204" comment="postgresql-odbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038205" comment="postgresql-perl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038206" comment="postgresql-python less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038207" comment="postgresql-server less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038208" comment="postgresql-tcl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038209" comment="postgresql less than 7.2.7-4"/>
		</criteria>
	</criteria>
	<!-- 631a12347810e4a9ff7c3bbaafbccd39 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038210" comment="postgresql-libs-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038211" comment="postgresql-contrib less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038212" comment="postgresql-devel less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038213" comment="postgresql-docs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038214" comment="postgresql-libs-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038215" comment="postgresql-libs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038216" comment="postgresql-pl less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038217" comment="postgresql-server less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038218" comment="postgresql less than 7.4.7-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038219" comment="postgresql-contrib less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038220" comment="postgresql-devel less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038221" comment="postgresql-docs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038222" comment="postgresql-libs-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038223" comment="postgresql-libs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038224" comment="postgresql-pl less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038225" comment="postgresql-server less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038226" comment="postgresql less than 8.0.1-6"/>
			</criteria>
		</criteria></criteria>
	<!-- 69187db2b25d279a07fa77241b629f8a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038227" comment="postgresql-devel less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038228" comment="postgresql-jdbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038229" comment="postgresql-libs less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038230" comment="postgresql-odbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038231" comment="postgresql-perl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038232" comment="postgresql-python less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038233" comment="postgresql-server less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038234" comment="postgresql-tcl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038235" comment="postgresql less than 7.2.8-2"/>
		</criteria>
	</criteria>
	<!-- 8522a86bfa9ca66f0b82fb3eb0042bae -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032778" comment="postgresql-libs-32bit less than 9-200506061933"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032779" comment="postgresql-libs-32bit less than 9-200506062151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032780" comment="postgresql-libs-64bit less than 9-200506062057"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032781" comment="postgresql-libs-x86 less than 9-200506061918"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria></criteria>
	<!-- c881b0eb54c9c29c35b7efe0a21e8e89 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038236" comment="postgresql-libs-32bit less than 9.1-200506061950"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038237" comment="postgresql-contrib less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038238" comment="postgresql-devel less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038239" comment="postgresql-docs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038240" comment="postgresql-libs-32bit less than 9.2-200506062019"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038241" comment="postgresql-libs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038242" comment="postgresql-pl less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038243" comment="postgresql-server less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038244" comment="postgresql less than 7.4.8-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038245" comment="postgresql-contrib less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038246" comment="postgresql-devel less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038247" comment="postgresql-docs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038248" comment="postgresql-libs-32bit less than 9.3-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038249" comment="postgresql-libs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038250" comment="postgresql-pl less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038251" comment="postgresql-server less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038252" comment="postgresql less than 8.0.3-1.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e782a2a7e7df8fe7a4f54f1fa8172438 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032782" comment="postgresql-libs-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032783" comment="postgresql-libs-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032784" comment="postgresql-libs-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032785" comment="postgresql-libs-x86 less than 9-200504131636"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050246" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0246</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0246" source="CVE"/>
	<description>
	The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 305407891b82a33f0b970b733fab4d70 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038201" comment="postgresql-devel less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038202" comment="postgresql-jdbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038203" comment="postgresql-libs less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038204" comment="postgresql-odbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038205" comment="postgresql-perl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038206" comment="postgresql-python less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038207" comment="postgresql-server less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038208" comment="postgresql-tcl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038209" comment="postgresql less than 7.2.7-4"/>
		</criteria>
	</criteria>
	<!-- 631a12347810e4a9ff7c3bbaafbccd39 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038210" comment="postgresql-libs-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038211" comment="postgresql-contrib less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038212" comment="postgresql-devel less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038213" comment="postgresql-docs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038214" comment="postgresql-libs-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038215" comment="postgresql-libs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038216" comment="postgresql-pl less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038217" comment="postgresql-server less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038218" comment="postgresql less than 7.4.7-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038219" comment="postgresql-contrib less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038220" comment="postgresql-devel less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038221" comment="postgresql-docs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038222" comment="postgresql-libs-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038223" comment="postgresql-libs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038224" comment="postgresql-pl less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038225" comment="postgresql-server less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038226" comment="postgresql less than 8.0.1-6"/>
			</criteria>
		</criteria></criteria>
	<!-- 69187db2b25d279a07fa77241b629f8a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038227" comment="postgresql-devel less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038228" comment="postgresql-jdbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038229" comment="postgresql-libs less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038230" comment="postgresql-odbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038231" comment="postgresql-perl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038232" comment="postgresql-python less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038233" comment="postgresql-server less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038234" comment="postgresql-tcl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038235" comment="postgresql less than 7.2.8-2"/>
		</criteria>
	</criteria>
	<!-- 8522a86bfa9ca66f0b82fb3eb0042bae -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032778" comment="postgresql-libs-32bit less than 9-200506061933"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032779" comment="postgresql-libs-32bit less than 9-200506062151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032780" comment="postgresql-libs-64bit less than 9-200506062057"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032781" comment="postgresql-libs-x86 less than 9-200506061918"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria></criteria>
	<!-- c881b0eb54c9c29c35b7efe0a21e8e89 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038236" comment="postgresql-libs-32bit less than 9.1-200506061950"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038237" comment="postgresql-contrib less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038238" comment="postgresql-devel less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038239" comment="postgresql-docs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038240" comment="postgresql-libs-32bit less than 9.2-200506062019"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038241" comment="postgresql-libs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038242" comment="postgresql-pl less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038243" comment="postgresql-server less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038244" comment="postgresql less than 7.4.8-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038245" comment="postgresql-contrib less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038246" comment="postgresql-devel less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038247" comment="postgresql-docs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038248" comment="postgresql-libs-32bit less than 9.3-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038249" comment="postgresql-libs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038250" comment="postgresql-pl less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038251" comment="postgresql-server less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038252" comment="postgresql less than 8.0.3-1.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e782a2a7e7df8fe7a4f54f1fa8172438 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032782" comment="postgresql-libs-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032783" comment="postgresql-libs-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032784" comment="postgresql-libs-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032785" comment="postgresql-libs-x86 less than 9-200504131636"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050247" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0247</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247" source="CVE"/>
	<description>
	Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 305407891b82a33f0b970b733fab4d70 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038201" comment="postgresql-devel less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038202" comment="postgresql-jdbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038203" comment="postgresql-libs less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038204" comment="postgresql-odbc less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038205" comment="postgresql-perl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038206" comment="postgresql-python less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038207" comment="postgresql-server less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038208" comment="postgresql-tcl less than 7.2.7-4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038209" comment="postgresql less than 7.2.7-4"/>
		</criteria>
	</criteria>
	<!-- 631a12347810e4a9ff7c3bbaafbccd39 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038210" comment="postgresql-libs-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038211" comment="postgresql-contrib less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038212" comment="postgresql-devel less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038213" comment="postgresql-docs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038214" comment="postgresql-libs-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038215" comment="postgresql-libs less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038216" comment="postgresql-pl less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038217" comment="postgresql-server less than 7.4.7-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038218" comment="postgresql less than 7.4.7-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038219" comment="postgresql-contrib less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038220" comment="postgresql-devel less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038221" comment="postgresql-docs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038222" comment="postgresql-libs-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038223" comment="postgresql-libs less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038224" comment="postgresql-pl less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038225" comment="postgresql-server less than 8.0.1-6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038226" comment="postgresql less than 8.0.1-6"/>
			</criteria>
		</criteria></criteria>
	<!-- 69187db2b25d279a07fa77241b629f8a -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038227" comment="postgresql-devel less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038228" comment="postgresql-jdbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038229" comment="postgresql-libs less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038230" comment="postgresql-odbc less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038231" comment="postgresql-perl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038232" comment="postgresql-python less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038233" comment="postgresql-server less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038234" comment="postgresql-tcl less than 7.2.8-2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038235" comment="postgresql less than 7.2.8-2"/>
		</criteria>
	</criteria>
	<!-- 8522a86bfa9ca66f0b82fb3eb0042bae -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032778" comment="postgresql-libs-32bit less than 9-200506061933"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032779" comment="postgresql-libs-32bit less than 9-200506062151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032780" comment="postgresql-libs-64bit less than 9-200506062057"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032781" comment="postgresql-libs-x86 less than 9-200506061918"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria></criteria>
	<!-- c881b0eb54c9c29c35b7efe0a21e8e89 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030494" comment="postgresql-contrib less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030495" comment="postgresql-devel less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030496" comment="postgresql-docs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038236" comment="postgresql-libs-32bit less than 9.1-200506061950"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030497" comment="postgresql-libs less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030498" comment="postgresql-pl less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030499" comment="postgresql-server less than 7.4.8-0.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030500" comment="postgresql less than 7.4.8-0.6"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038237" comment="postgresql-contrib less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038238" comment="postgresql-devel less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038239" comment="postgresql-docs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038240" comment="postgresql-libs-32bit less than 9.2-200506062019"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038241" comment="postgresql-libs less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038242" comment="postgresql-pl less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038243" comment="postgresql-server less than 7.4.8-0.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038244" comment="postgresql less than 7.4.8-0.3"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038245" comment="postgresql-contrib less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038246" comment="postgresql-devel less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038247" comment="postgresql-docs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038248" comment="postgresql-libs-32bit less than 9.3-7.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038249" comment="postgresql-libs less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038250" comment="postgresql-pl less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038251" comment="postgresql-server less than 8.0.3-1.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038252" comment="postgresql less than 8.0.3-1.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e782a2a7e7df8fe7a4f54f1fa8172438 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032782" comment="postgresql-libs-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032783" comment="postgresql-libs-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032784" comment="postgresql-libs-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032785" comment="postgresql-libs-x86 less than 9-200504131636"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030501" comment="postgresql-contrib less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030502" comment="postgresql-devel less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030503" comment="postgresql-docs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030504" comment="postgresql-libs less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030505" comment="postgresql-pl less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030506" comment="postgresql-server less than 7.4.7-0.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030507" comment="postgresql less than 7.4.7-0.5"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050255" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0255</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255" source="CVE"/>
	<description>
	String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a51f0a3982f40ddfe509b210b6288bd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030508" comment="MozillaFirefox-translations less than 1.0.1-9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030509" comment="MozillaFirefox less than 1.0.1-9.1"/>
		</criteria>
	</criteria>
	<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050366" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0366</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0366" source="CVE"/>
	<description>
	The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.
	</description>
 </metadata>
<!-- 91bd5b75ab1218a3ee7853871ac831ce -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030510" comment="gpg less than 1.2.4-68.7"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038269" comment="gpg less than 1.2.2rc1-114"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038270" comment="gpg less than 1.0.7-179"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050373" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0373</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2005-0373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0373" source="CVE"/>
	<description>
	Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 231841f94b974632df612072f02006f2 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032787" comment="cyrus-sasl-32bit less than 9-200502182129"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032788" comment="cyrus-sasl-32bit less than 9-200502182158"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032789" comment="cyrus-sasl-64bit less than 9-200502182226"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032790" comment="cyrus-sasl-x86 less than 9-200502182119"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030511" comment="cyrus-sasl less than 2.1.18-33.8"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030511" comment="cyrus-sasl less than 2.1.18-33.8"/>
		</criteria></criteria>
	<!-- b8382ae8e8f8dbc1dc6d6046c214b9a4 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038271" comment="cyrus-sasl2 less than 2.1.7-128"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050384" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0384</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0384" source="CVE"/>
	<description>
	Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 6b993af03cbdac52472a99cfcb5d9c0b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038131" comment="k_athlon less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038132" comment="k_deflt less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038133" comment="k_psmp less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038134" comment="k_smp less than 2.4.19-378"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038135" comment="kernel-source less than 2.4.19.SuSE-378"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050397" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0397</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
	</affected>
	<reference ref_id="CVE-2005-0397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0397" source="CVE"/>
	<description>
	Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1490ed18ddb279674a13c8504396e7ca -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030512" comment="ImageMagick-devel less than 5.5.7-225.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030513" comment="ImageMagick less than 5.5.7-225.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038272" comment="ImageMagick-Magick++ less than 5.5.7-225.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030512" comment="ImageMagick-devel less than 5.5.7-225.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030513" comment="ImageMagick less than 5.5.7-225.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038273" comment="perl-PerlMagick less than 5.5.7-225.15"/>
			</criteria>
		</criteria></criteria>
	<!-- e27323d0cfc430ce6b42ffb8ff31939f -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038274" comment="ImageMagick less than 5.4.7-279"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050399" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0399</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399" source="CVE"/>
	<description>
	Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050400" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0400</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0400" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0400" source="CVE"/>
	<description>
	The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 012927c610add3677c52ec3a28a1648d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 309fc14e1d18412dbf174319b55459e0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032791" comment="kernel-s390x less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 3d61d15f4e0e49c7e669b2c2b1d53281 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038275" comment="k_athlon less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038276" comment="k_deflt less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038277" comment="k_psmp less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038278" comment="k_smp less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038279" comment="kernel-source less than 2.4.19.SuSE-383"/>
		</criteria>
	</criteria>
	<!-- 64251c053da708b39de6775b1dfb2ee3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038281" comment="k_numa less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 679c9816ba170a623707b09e28fd0fd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038284" comment="kernel-iseries64 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038285" comment="kernel-ppc64 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 68c69c48914f4449e711808448aefd2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032792" comment="kernel-iseries64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032793" comment="kernel-pmac64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032794" comment="kernel-pseries64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 8018e25a083d0b5870eba427903d4e85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038286" comment="Intel-536ep less than 4.69-10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038287" comment="dprobes less than 3.6.5-8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038288" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038289" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038290" comment="kernel-bigsmp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038291" comment="kernel-bigsmp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038292" comment="kernel-default-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038293" comment="kernel-default-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038294" comment="kernel-default less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038295" comment="kernel-default less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038296" comment="kernel-docs less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038297" comment="kernel-docs less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038298" comment="kernel-smp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038299" comment="kernel-smp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038300" comment="kernel-smp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038301" comment="kernel-smp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038302" comment="kernel-source less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038303" comment="kernel-source less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038304" comment="kernel-syms less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038305" comment="kernel-syms less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038306" comment="kernel-um-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038307" comment="kernel-um-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038308" comment="kernel-um less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038309" comment="kernel-um less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038310" comment="kernel-xen-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038311" comment="kernel-xen-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038312" comment="kernel-xen less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038313" comment="kernel-xen less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038314" comment="ltmodem less than 8.31a10-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038315" comment="um-host-install-initrd less than 1.0-50.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038316" comment="um-host-kernel less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038317" comment="um-host-kernel less than 2.6.11.4-21.7"/>
		</criteria>
	</criteria>
	<!-- 8a7a62bd2689c5729cb258075912cd07 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032795" comment="kernel-s390 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 8cb0aa3b1ee5031c67c4ee14f4858126 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 928c182f4ce54092ec84d122124335ca -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032796" comment="kernel-64k-pagesize less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032797" comment="kernel-debug less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032798" comment="kernel-sn2 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- a3b07ca3609dec4a6eaba721000098e2 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038318" comment="k_athlon less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038319" comment="k_debug less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038320" comment="k_psmp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- d47bda72442464a1dede0e81b32d7ca8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- d616efaaa3764b063cc5bd3d6d09c89e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030518" comment="kernel-bigsmp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032797" comment="kernel-debug less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032799" comment="kernel-um less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032800" comment="um-host-install-initrd less than 1.0-48.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032801" comment="um-host-kernel less than 2.6.5-7.155.29"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030518" comment="kernel-bigsmp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
			</criteria>
		</criteria></criteria>
	<!-- f0f03f02699b998edb62098de7b55696 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038321" comment="k_itanium2-smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038322" comment="k_itanium2 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038323" comment="k_page-64k less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050446" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0446</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0446" source="CVE"/>
	<description>
	Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.
	</description>
 </metadata>
<!-- 46d04b64d752063540e49f5a56c6f3c3 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032786" comment="squid less than 2.5.STABLE5-42.30"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038268" comment="squid less than 2.4.STABLE7-293"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050449" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0449</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0449" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0449" source="CVE"/>
	<description>
	The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050455" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0455</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
	</affected>
	<reference ref_id="CVE-2005-0455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0455" source="CVE"/>
	<description>
	Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.
	</description>
 </metadata>
<!-- bd4aed60b3fec6205fd20cd615124c7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030519" comment="RealPlayer less than 10.0.3-0.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050468" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0468</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468" source="CVE"/>
	<description>
	Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 64c29e56970f2633ff2ac802beb243d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038324" comment="heimdal-lib less than 0.4e-409"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038325" comment="heimdal less than 0.4e-409"/>
		</criteria>
	</criteria>
	<!-- 9220bf6740fd5cf5ad22d9b2ec48506c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038326" comment="telnet less than 1.1-44.2"/>
	</criteria>
	<!-- b1e64e238134069ad4b3519f91102157 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030520" comment="telnet less than 1.1-38.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038327" comment="telnet less than 1.0-526"/>
		</criteria></criteria>
	<!-- c3eba5032aa49dac64765a0316cf948a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032802" comment="heimdal-devel-32bit less than 9-200504071809"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032803" comment="heimdal-devel-32bit less than 9-200504072000"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032804" comment="heimdal-devel-64bit less than 9-200504071906"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030521" comment="heimdal-devel less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032805" comment="heimdal-lib-32bit less than 9-200504071809"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032806" comment="heimdal-lib-32bit less than 9-200504072000"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032807" comment="heimdal-lib-64bit less than 9-200504071906"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032808" comment="heimdal-lib-x86 less than 9-200504071757"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030522" comment="heimdal-lib less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030523" comment="heimdal less than 0.6.1rc3-55.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030521" comment="heimdal-devel less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030522" comment="heimdal-lib less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030523" comment="heimdal less than 0.6.1rc3-55.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038328" comment="heimdal-devel less than 0.4e-408"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038329" comment="heimdal-lib less than 0.4e-408"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038330" comment="heimdal less than 0.4e-408"/>
			</criteria>
		</criteria></criteria>
	<!-- d186f2c228e08c5865db6bb658b39807 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030524" comment="telnet less than 1.1-38.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038331" comment="telnet less than 1.0-530"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050469" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0469</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469" source="CVE"/>
	<description>
	Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 64c29e56970f2633ff2ac802beb243d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038324" comment="heimdal-lib less than 0.4e-409"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038325" comment="heimdal less than 0.4e-409"/>
		</criteria>
	</criteria>
	<!-- 9220bf6740fd5cf5ad22d9b2ec48506c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038326" comment="telnet less than 1.1-44.2"/>
	</criteria>
	<!-- b1e64e238134069ad4b3519f91102157 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030520" comment="telnet less than 1.1-38.6"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038327" comment="telnet less than 1.0-526"/>
		</criteria></criteria>
	<!-- c3eba5032aa49dac64765a0316cf948a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032802" comment="heimdal-devel-32bit less than 9-200504071809"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032803" comment="heimdal-devel-32bit less than 9-200504072000"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032804" comment="heimdal-devel-64bit less than 9-200504071906"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030521" comment="heimdal-devel less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032805" comment="heimdal-lib-32bit less than 9-200504071809"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032806" comment="heimdal-lib-32bit less than 9-200504072000"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032807" comment="heimdal-lib-64bit less than 9-200504071906"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032808" comment="heimdal-lib-x86 less than 9-200504071757"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030522" comment="heimdal-lib less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030523" comment="heimdal less than 0.6.1rc3-55.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030521" comment="heimdal-devel less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030522" comment="heimdal-lib less than 0.6.1rc3-55.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030523" comment="heimdal less than 0.6.1rc3-55.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038328" comment="heimdal-devel less than 0.4e-408"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038329" comment="heimdal-lib less than 0.4e-408"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038330" comment="heimdal less than 0.4e-408"/>
			</criteria>
		</criteria></criteria>
	<!-- d186f2c228e08c5865db6bb658b39807 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030524" comment="telnet less than 1.1-38.9"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038331" comment="telnet less than 1.0-530"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050472" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0472</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0472" source="CVE"/>
	<description>
	Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- c432039b13c44620b98118239ad45b24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038332" comment="gaim less than 0.59-181"/>
	</criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050473" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0473</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0473" source="CVE"/>
	<description>
	The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050488" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0488</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0488" source="CVE"/>
	<description>
	Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
	</description>
 </metadata>
<!-- d186f2c228e08c5865db6bb658b39807 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030524" comment="telnet less than 1.1-38.9"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038331" comment="telnet less than 1.0-530"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050504" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0504</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0504" source="CVE"/>
	<description>
	Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050524" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0524</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0524" source="CVE"/>
	<description>
	The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 07fd95b3f9739b88441090b546febd79 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038016" comment="mod_php4-core less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038017" comment="mod_php4-devel less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038018" comment="mod_php4-servlet less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038019" comment="mod_php4 less than 4.2.2-491"/>
		</criteria>
	</criteria>
	<!-- 2e855be5ae7903ca40477ba01d9c9d02 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 36e362824c8445edae5f3b24fb94c803 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038333" comment="apache2-mod_php5 less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038334" comment="php5-devel less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038335" comment="php5-exif less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038336" comment="php5-fastcgi less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038337" comment="php5-pear less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038338" comment="php5-sysvmsg less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038339" comment="php5-sysvshm less than 5.0.3-14.9"/>
		</criteria>
	</criteria>
	<!-- 487ffe8f95e8ee6f115c76022fd38247 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038340" comment="apache2-mod_php4 less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038341" comment="mod_php4-servlet less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038342" comment="php4-32bit less than 9.3-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038343" comment="php4-devel less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038344" comment="php4-exif less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038345" comment="php4-fastcgi less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038346" comment="php4-pear less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038347" comment="php4-session less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038348" comment="php4-sysvshm less than 4.3.10-14.11"/>
		</criteria>
	</criteria>
	<!-- 58fef4bdbacb5786518cae78c3751c41 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038349" comment="apache2-mod_php4 less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038350" comment="mod_php4-servlet less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038351" comment="php4-32bit less than 9.3-7.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038352" comment="php4-devel less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038353" comment="php4-exif less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038354" comment="php4-fastcgi less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038355" comment="php4-pear less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038356" comment="php4-session less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038357" comment="php4-sysvshm less than 4.3.10-14.6"/>
		</criteria>
	</criteria>
	<!-- 63683990c0d9230597486a2543e2ef74 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038358" comment="apache2-mod_php5 less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038359" comment="php4-exif less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038360" comment="php5-devel less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038361" comment="php5-fastcgi less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038362" comment="php5-sysvmsg less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038363" comment="php5-sysvshm less than 5.0.3-14.4"/>
		</criteria>
	</criteria>
	<!-- 741b97d2ff31a96a2d83a1dcab427bda -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038364" comment="apache2-mod_php4 less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038365" comment="mod_php4-servlet less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038366" comment="php4-32bit less than 9.3-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038367" comment="php4-devel less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038368" comment="php4-fastcgi less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038369" comment="php4-session less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038370" comment="php4-sysvshm less than 4.3.10-14.2"/>
		</criteria>
	</criteria>
	<!-- 7f36b0314c2e0cdee069a52ce4289795 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032666" comment="mod_php4-servlet less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 82f1ecb575b4db26a33d6d578ce464ea -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038371" comment="apache2-mod_php5 less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038372" comment="php5-devel less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038373" comment="php5-exif less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038374" comment="php5-fastcgi less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038375" comment="php5-pear less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038376" comment="php5-sysvmsg less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038377" comment="php5-sysvshm less than 5.0.3-14.6"/>
		</criteria>
	</criteria>
	<!-- 865dd631aaa5d77384d791a67fc86c6d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038020" comment="mod_php4-core less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038021" comment="mod_php4-devel less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038022" comment="mod_php4-servlet less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038023" comment="mod_php4 less than 4.2.2-489"/>
		</criteria>
	</criteria>
	<!-- 8e92be327165b504dec328c05ca4220b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032678" comment="mod_php4-servlet less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- 96d092ab1925ede50674a8e6febbc9ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 981ef108b964d6518c58b160d56e9bcc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032687" comment="mod_php4-servlet less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 9ada24b19cd6ee9fcc2cba9cfb0865e8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038378" comment="apache2-mod_php5 less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038379" comment="php5-devel less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038380" comment="php5-fastcgi less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038381" comment="php5-sysvmsg less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038382" comment="php5-sysvshm less than 5.0.3-14.2"/>
		</criteria>
	</criteria>
	<!-- b0cc027d40188c4f2c516845c31cc69f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- b1e3cb26e3f95c7ba41856915752ed97 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038383" comment="apache2-mod_php5 less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038384" comment="php5-devel less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038385" comment="php5-exif less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038386" comment="php5-fastcgi less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038387" comment="php5-pear less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038388" comment="php5-sysvmsg less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038389" comment="php5-sysvshm less than 5.0.3-14.11"/>
		</criteria>
	</criteria>
	<!-- ba2325a214aeb9526916f1f3a255babd -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038024" comment="mod_php4-core less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038025" comment="mod_php4-devel less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038026" comment="mod_php4-servlet less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038027" comment="mod_php4 less than 4.2.2-487"/>
		</criteria>
	</criteria>
	<!-- bb15f54cd03e743f9f9dd09ccc912493 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032692" comment="mod_php4-servlet less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ca818371bc02684932f162c95087c026 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038028" comment="mod_php4-core less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038029" comment="mod_php4-devel less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038030" comment="mod_php4-servlet less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038031" comment="mod_php4 less than 4.2.2-493"/>
		</criteria>
	</criteria>
	<!-- cc880d8594257d1c37f5c5e40549ab75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ccc76126b61f83a7e298f93f2337dd33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038390" comment="apache2-mod_php4 less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038391" comment="mod_php4-servlet less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038392" comment="php4-32bit less than 9.3-7.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038393" comment="php4-devel less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038359" comment="php4-exif less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038394" comment="php4-fastcgi less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038395" comment="php4-session less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038396" comment="php4-sysvshm less than 4.3.10-14.4"/>
		</criteria>
	</criteria>
	<!-- d423945b493bfda194a01e10544e9032 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038358" comment="apache2-mod_php5 less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038360" comment="php5-devel less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038397" comment="php5-exif less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038361" comment="php5-fastcgi less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038362" comment="php5-sysvmsg less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038363" comment="php5-sysvshm less than 5.0.3-14.4"/>
		</criteria>
	</criteria>
	<!-- dde975d7f1cfd346b795ad08d61a21f4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038398" comment="apache2-mod_php4 less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038399" comment="mod_php4-servlet less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038400" comment="php4-32bit less than 9.3-7.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038401" comment="php4-devel less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038402" comment="php4-exif less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038403" comment="php4-fastcgi less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038404" comment="php4-pear less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038405" comment="php4-session less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038406" comment="php4-sysvshm less than 4.3.10-14.9"/>
		</criteria>
	</criteria>
	<!-- eb6734193188e5e67d6f06e03c942de2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
	<!-- ee8460dd87ca30f8864ad2c388d24504 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032716" comment="mod_php4-servlet less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050525" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0525</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0525" source="CVE"/>
	<description>
	The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 07fd95b3f9739b88441090b546febd79 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038016" comment="mod_php4-core less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038017" comment="mod_php4-devel less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038018" comment="mod_php4-servlet less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038019" comment="mod_php4 less than 4.2.2-491"/>
		</criteria>
	</criteria>
	<!-- 2e855be5ae7903ca40477ba01d9c9d02 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 36e362824c8445edae5f3b24fb94c803 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038333" comment="apache2-mod_php5 less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038334" comment="php5-devel less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038335" comment="php5-exif less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038336" comment="php5-fastcgi less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038337" comment="php5-pear less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038338" comment="php5-sysvmsg less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038339" comment="php5-sysvshm less than 5.0.3-14.9"/>
		</criteria>
	</criteria>
	<!-- 487ffe8f95e8ee6f115c76022fd38247 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038340" comment="apache2-mod_php4 less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038341" comment="mod_php4-servlet less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038342" comment="php4-32bit less than 9.3-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038343" comment="php4-devel less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038344" comment="php4-exif less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038345" comment="php4-fastcgi less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038346" comment="php4-pear less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038347" comment="php4-session less than 4.3.10-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038348" comment="php4-sysvshm less than 4.3.10-14.11"/>
		</criteria>
	</criteria>
	<!-- 58fef4bdbacb5786518cae78c3751c41 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038349" comment="apache2-mod_php4 less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038350" comment="mod_php4-servlet less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038351" comment="php4-32bit less than 9.3-7.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038352" comment="php4-devel less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038353" comment="php4-exif less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038354" comment="php4-fastcgi less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038355" comment="php4-pear less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038356" comment="php4-session less than 4.3.10-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038357" comment="php4-sysvshm less than 4.3.10-14.6"/>
		</criteria>
	</criteria>
	<!-- 63683990c0d9230597486a2543e2ef74 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038358" comment="apache2-mod_php5 less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038359" comment="php4-exif less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038360" comment="php5-devel less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038361" comment="php5-fastcgi less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038362" comment="php5-sysvmsg less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038363" comment="php5-sysvshm less than 5.0.3-14.4"/>
		</criteria>
	</criteria>
	<!-- 741b97d2ff31a96a2d83a1dcab427bda -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038364" comment="apache2-mod_php4 less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038365" comment="mod_php4-servlet less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038366" comment="php4-32bit less than 9.3-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038367" comment="php4-devel less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038368" comment="php4-fastcgi less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038369" comment="php4-session less than 4.3.10-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038370" comment="php4-sysvshm less than 4.3.10-14.2"/>
		</criteria>
	</criteria>
	<!-- 7f36b0314c2e0cdee069a52ce4289795 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032666" comment="mod_php4-servlet less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 82f1ecb575b4db26a33d6d578ce464ea -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038371" comment="apache2-mod_php5 less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038372" comment="php5-devel less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038373" comment="php5-exif less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038374" comment="php5-fastcgi less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038375" comment="php5-pear less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038376" comment="php5-sysvmsg less than 5.0.3-14.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038377" comment="php5-sysvshm less than 5.0.3-14.6"/>
		</criteria>
	</criteria>
	<!-- 865dd631aaa5d77384d791a67fc86c6d -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038020" comment="mod_php4-core less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038021" comment="mod_php4-devel less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038022" comment="mod_php4-servlet less than 4.2.2-489"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038023" comment="mod_php4 less than 4.2.2-489"/>
		</criteria>
	</criteria>
	<!-- 8e92be327165b504dec328c05ca4220b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032678" comment="mod_php4-servlet less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- 96d092ab1925ede50674a8e6febbc9ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032663" comment="apache-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032664" comment="apache2-mod_php4 less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032665" comment="mod_php4-core less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032667" comment="php4-devel less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032668" comment="php4-exif less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032669" comment="php4-fastcgi less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032670" comment="php4-imap less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032671" comment="php4-mysql less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032672" comment="php4-pear less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032673" comment="php4-session less than 4.3.4-43.41"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032674" comment="php4-sysvshm less than 4.3.4-43.41"/>
		</criteria>
	</criteria>
	<!-- 981ef108b964d6518c58b160d56e9bcc -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-nlpos is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032687" comment="mod_php4-servlet less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 9ada24b19cd6ee9fcc2cba9cfb0865e8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038378" comment="apache2-mod_php5 less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038379" comment="php5-devel less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038380" comment="php5-fastcgi less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038381" comment="php5-sysvmsg less than 5.0.3-14.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038382" comment="php5-sysvshm less than 5.0.3-14.2"/>
		</criteria>
	</criteria>
	<!-- b0cc027d40188c4f2c516845c31cc69f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032675" comment="apache-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032676" comment="apache2-mod_php4 less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032677" comment="mod_php4-core less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032679" comment="php4-devel less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032680" comment="php4-exif less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032681" comment="php4-fastcgi less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032682" comment="php4-imap less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032683" comment="php4-mysql less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032684" comment="php4-pear less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032685" comment="php4-session less than 4.3.4-43.36"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032686" comment="php4-sysvshm less than 4.3.4-43.36"/>
		</criteria>
	</criteria>
	<!-- b1e3cb26e3f95c7ba41856915752ed97 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038383" comment="apache2-mod_php5 less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038384" comment="php5-devel less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038385" comment="php5-exif less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038386" comment="php5-fastcgi less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038387" comment="php5-pear less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038388" comment="php5-sysvmsg less than 5.0.3-14.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038389" comment="php5-sysvshm less than 5.0.3-14.11"/>
		</criteria>
	</criteria>
	<!-- ba2325a214aeb9526916f1f3a255babd -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038024" comment="mod_php4-core less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038025" comment="mod_php4-devel less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038026" comment="mod_php4-servlet less than 4.2.2-487"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038027" comment="mod_php4 less than 4.2.2-487"/>
		</criteria>
	</criteria>
	<!-- bb15f54cd03e743f9f9dd09ccc912493 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032692" comment="mod_php4-servlet less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ca818371bc02684932f162c95087c026 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038028" comment="mod_php4-core less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038029" comment="mod_php4-devel less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038030" comment="mod_php4-servlet less than 4.2.2-493"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038031" comment="mod_php4 less than 4.2.2-493"/>
		</criteria>
	</criteria>
	<!-- cc880d8594257d1c37f5c5e40549ab75 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032689" comment="apache-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032690" comment="apache2-mod_php4 less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032691" comment="mod_php4-core less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032693" comment="php4-devel less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032694" comment="php4-exif less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032695" comment="php4-fastcgi less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032696" comment="php4-imap less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032697" comment="php4-mysql less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032698" comment="php4-session less than 4.3.4-43.31"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032699" comment="php4-sysvshm less than 4.3.4-43.31"/>
		</criteria>
	</criteria>
	<!-- ccc76126b61f83a7e298f93f2337dd33 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038390" comment="apache2-mod_php4 less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038391" comment="mod_php4-servlet less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038392" comment="php4-32bit less than 9.3-7.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038393" comment="php4-devel less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038359" comment="php4-exif less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038394" comment="php4-fastcgi less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038395" comment="php4-session less than 4.3.10-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038396" comment="php4-sysvshm less than 4.3.10-14.4"/>
		</criteria>
	</criteria>
	<!-- d423945b493bfda194a01e10544e9032 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038358" comment="apache2-mod_php5 less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038360" comment="php5-devel less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038397" comment="php5-exif less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038361" comment="php5-fastcgi less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038362" comment="php5-sysvmsg less than 5.0.3-14.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038363" comment="php5-sysvshm less than 5.0.3-14.4"/>
		</criteria>
	</criteria>
	<!-- dde975d7f1cfd346b795ad08d61a21f4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038398" comment="apache2-mod_php4 less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038399" comment="mod_php4-servlet less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038400" comment="php4-32bit less than 9.3-7.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038401" comment="php4-devel less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038402" comment="php4-exif less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038403" comment="php4-fastcgi less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038404" comment="php4-pear less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038405" comment="php4-session less than 4.3.10-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038406" comment="php4-sysvshm less than 4.3.10-14.9"/>
		</criteria>
	</criteria>
	<!-- eb6734193188e5e67d6f06e03c942de2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
	<!-- ee8460dd87ca30f8864ad2c388d24504 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032707" comment="apache-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032708" comment="apache2-mod_php4 less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032709" comment="mod_php4-core less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032716" comment="mod_php4-servlet less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032710" comment="php4-devel less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032711" comment="php4-fastcgi less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032712" comment="php4-imap less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032713" comment="php4-mysql less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032714" comment="php4-session less than 4.3.4-43.28"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032715" comment="php4-sysvshm less than 4.3.4-43.28"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050529" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0529</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0529" source="CVE"/>
	<description>
	Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050530" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0530</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0530" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0530" source="CVE"/>
	<description>
	Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 235e46b936ede0d09e4a5a543a8f2587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032564" comment="drbd less than 0.7.5-0.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032565" comment="km_drbd less than 0.7.5-0.16"/>
		</criteria>
	</criteria>
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050532" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0532</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0532" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0532" source="CVE"/>
	<description>
	The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between size_t and int data types.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2558830537429cdedb543926fd6344a8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 33bbbc88aace49aa6b5ad80876cc4083 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032566" comment="kernel-64k-pagesize less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032568" comment="kernel-sn2 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- 54a1f3c286aab229c33a01a912db9ffa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032567" comment="kernel-debug less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032569" comment="kernel-um less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032570" comment="um-host-install-initrd less than 1.0-48.6"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032571" comment="um-host-kernel less than 2.6.5-7.151"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030421" comment="kernel-bigsmp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
			</criteria>
		</criteria></criteria>
	<!-- 6a60dcc7566d6e55e403322b85680b5a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032572" comment="kernel-s390 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- aa4e2819d48d9123020c49d010c105a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032573" comment="kernel-s390x less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
	<!-- b47839236d4235af750bf0cf0143b9d6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030417" comment="kernel-default less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032574" comment="kernel-iseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032575" comment="kernel-pmac64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032576" comment="kernel-pseries64 less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030418" comment="kernel-smp less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030419" comment="kernel-source less than 2.6.5-7.151"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030420" comment="kernel-syms less than 2.6.5-7.151"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050587" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0587</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0587" source="CVE"/>
	<description>
	Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050590" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0590</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0590" source="CVE"/>
	<description>
	The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050592" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0592</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0592" source="CVE"/>
	<description>
	Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
	</description>
 </metadata>
<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050605" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0605</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0605" source="CVE"/>
	<description>
	scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 36132eb8edc63ec4babd0883f41c5624 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038407" comment="xshared less than 4.2.0-272"/>
	</criteria>
	<!-- da039ce086e1ed3aac07762982d8569f -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032809" comment="XFree86-libs-32bit less than 9-200504020902"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032810" comment="XFree86-libs-32bit less than 9-200504020922"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032811" comment="XFree86-libs-64bit less than 9-200504020324"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032812" comment="XFree86-libs-x86 less than 9-200504021401"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030525" comment="XFree86-libs less than 4.3.99.902-43.42.5"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038408" comment="XFree86-libs less than 4.3.0-136"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030525" comment="XFree86-libs less than 4.3.99.902-43.42.5"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050611" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0611</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
	</affected>
	<reference ref_id="CVE-2005-0611" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0611" source="CVE"/>
	<description>
	Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.
	</description>
 </metadata>
<!-- bd4aed60b3fec6205fd20cd615124c7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030519" comment="RealPlayer less than 10.0.3-0.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050626" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0626</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0626" source="CVE"/>
	<description>
	Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 322aa3ab64607261c8f3e8de31c8f138 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038409" comment="squid less than 2.5.STABLE1-112"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038410" comment="squid less than 2.5.STABLE3-124"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032813" comment="squid less than 2.5.STABLE5-42.38"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038411" comment="squid less than 2.5.STABLE6-6.13"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038412" comment="squid less than 2.5.STABLE9-4.2"/>
		</criteria></criteria>
	<!-- 376d684bc4c52e058376c0b2c1f41fd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032813" comment="squid less than 2.5.STABLE5-42.38"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038413" comment="squid less than 2.4.STABLE7-295"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050638" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0638</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0638" source="CVE"/>
	<description>
	xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
	</description>
 </metadata>
<!-- c05303031c7102a6a7ef04484f233a9f -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038414" comment="xli less than 1.17.0-304"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038415" comment="xli less than 1.17.0-298.2"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038416" comment="xli less than 1.17.0-299.2"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038417" comment="xli less than 1.17.0-300.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050664" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0664</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 10.1</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0664" source="CVE"/>
	<description>
	Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6770ca2dcf45cd86505302d8123f5d04 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038418" comment="kdegraphics3 less than 3.4.2-12.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037778" comment="suse101 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038419" comment="kdegraphics3 less than 3.5.1-23.9"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038420" comment="kdegraphics3 less than 3.4.0-11.7"/>
		</criteria></criteria>
	<!-- b6ccb42743ea150e59a03926ddc82eff -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038421" comment="libexif5 less than 0.5.12-3.2"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038422" comment="libexif5 less than 0.5.12-4.2"/>
		</criteria></criteria>
	<!-- d8cf9a498a682c8218818f0af83739a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030526" comment="libexif less than 0.5.12-118.7"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038423" comment="libexif less than 0.5.3-109"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050665" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0665</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0665" source="CVE"/>
	<description>
	Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 43b2efb78bbe436ccffb6340ffdaa616 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
	</criteria>
	<!-- 4e0ef0b05402f48b97d810e9f5177759 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038145" comment="xv less than 3.10a-1076"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038144" comment="xv less than 3.10a-1053.12"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038146" comment="xv less than 3.10a-1062.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038147" comment="xv less than 3.10a-1069.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050667" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0667</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0667" source="CVE"/>
	<description>
	Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
	</description>
 </metadata>
<!-- 7756ea87e70a95041e37b72aac519540 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038424" comment="sylpheed-claws less than 0.9.12-3.2"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038425" comment="sylpheed-claws less than 1.0.3-3.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050699" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0699</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0699" source="CVE"/>
	<description>
	Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.
	</description>
 </metadata>
<!-- 04002f442555d12065ebb4ba411fe086 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050706" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0706</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0706" source="CVE"/>
	<description>
	Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6e8b9da54a654fd68b754c2b999808d9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032424" comment="gnome-vfs less than 1.0.5-806.7"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037642" comment="gnome-vfs less than 1.0.5-822"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria></criteria>
	<!-- 7f86db7e0c063af0a4b3738c4b6d26be -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037644" comment="gnome-vfs2 less than 2.2.1-161"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037645" comment="gnome-vfs2 less than 2.0.2-271"/>
		</criteria></criteria>
	<!-- 91c2a897f0e315435a88f998cbc90b80 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038426" comment="grip less than 3.0.5-248"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038427" comment="grip less than 3.1.4-37.2"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038428" comment="grip less than 3.2.0-7.2"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038429" comment="grip less than 3.2.0-8.2"/>
		</criteria></criteria>
	<!-- a9b2b8c3a049831dfe42a9cc69112c52 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032425" comment="gnome-vfs2-32bit less than 9-200504131658"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032426" comment="gnome-vfs2-32bit less than 9-200504132031"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032427" comment="gnome-vfs2-64bit less than 9-200504131529"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030412" comment="gnome-vfs2-32bit less than 9-200504132212"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030413" comment="gnome-vfs2-doc less than 2.6.1-6.23"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030414" comment="gnome-vfs2 less than 2.6.1-6.23"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria></criteria>
	<!-- c114346c1dfffbd81602370d1f2cb899 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037650" comment="gnome-vfs2-doc less than 2.2.1-159"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037651" comment="gnome-vfs2 less than 2.2.1-159"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037653" comment="gnome-vfs2-doc less than 2.2.5-128"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037654" comment="gnome-vfs2 less than 2.2.5-128"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037656" comment="gnome-vfs2-32bit less than 9.1-200504131537"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032428" comment="gnome-vfs2-doc less than 2.4.2-68.9"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032429" comment="gnome-vfs2 less than 2.4.2-68.9"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037658" comment="gnome-vfs2-32bit less than 9.2-200504131606"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037659" comment="gnome-vfs2-doc less than 2.6.1-38.4"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037660" comment="gnome-vfs2 less than 2.6.1-38.4"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037662" comment="gnome-vfs2-32bit less than 9.3-7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037663" comment="gnome-vfs2-doc less than 2.10.0-14.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037664" comment="gnome-vfs2 less than 2.10.0-14.2"/>
			</criteria>
		</criteria></criteria>
	<!-- cb5dd06c287acb5bb44404f77353e379 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037643" comment="gnome-vfs less than 1.0.5-823"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032424" comment="gnome-vfs less than 1.0.5-806.7"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037665" comment="gnome-vfs less than 1.0.5-808.4"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037666" comment="gnome-vfs less than 1.0.5-816.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050709" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0709</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0709" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0709" source="CVE"/>
	<description>
	MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050710" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0710</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0710" source="CVE"/>
	<description>
	MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050711" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0711</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0711" source="CVE"/>
	<description>
	MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 19ed94f90bf16ea19b3c563f59dd7047 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009037799" comment="mysql less than 3.23.52-128"/>
	</criteria>
	<!-- 83b0f5c39630e68ca3757f1fa7fb1b42 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030424" comment="mysql-Max less than 4.0.18-32.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030425" comment="mysql less than 4.0.18-32.13"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050718" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0718</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0718" source="CVE"/>
	<description>
	Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 322aa3ab64607261c8f3e8de31c8f138 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038409" comment="squid less than 2.5.STABLE1-112"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038410" comment="squid less than 2.5.STABLE3-124"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032813" comment="squid less than 2.5.STABLE5-42.38"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038411" comment="squid less than 2.5.STABLE6-6.13"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038412" comment="squid less than 2.5.STABLE9-4.2"/>
		</criteria></criteria>
	<!-- 376d684bc4c52e058376c0b2c1f41fd8 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032813" comment="squid less than 2.5.STABLE5-42.38"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038413" comment="squid less than 2.4.STABLE7-295"/>
		</criteria></criteria>
	<!-- fce96418deb2ca446635af24ff7e4a01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032814" comment="squid less than 2.5.STABLE5-42.33"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050739" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0739</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0739" source="CVE"/>
	<description>
	The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
	</description>
 </metadata>
<!-- 04002f442555d12065ebb4ba411fe086 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032727" comment="ethereal less than 0.10.3-15.15"/>
	</criteria>
		<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038075" comment="ethereal less than 0.10.3-32"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050749" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0749</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0749" source="CVE"/>
	<description>
	The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 012927c610add3677c52ec3a28a1648d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 309fc14e1d18412dbf174319b55459e0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032791" comment="kernel-s390x less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 3d61d15f4e0e49c7e669b2c2b1d53281 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038275" comment="k_athlon less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038276" comment="k_deflt less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038277" comment="k_psmp less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038278" comment="k_smp less than 2.4.19-383"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038279" comment="kernel-source less than 2.4.19.SuSE-383"/>
		</criteria>
	</criteria>
	<!-- 64251c053da708b39de6775b1dfb2ee3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038281" comment="k_numa less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 679c9816ba170a623707b09e28fd0fd7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038284" comment="kernel-iseries64 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038285" comment="kernel-ppc64 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 68c69c48914f4449e711808448aefd2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032792" comment="kernel-iseries64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032793" comment="kernel-pmac64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032794" comment="kernel-pseries64 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 8018e25a083d0b5870eba427903d4e85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038286" comment="Intel-536ep less than 4.69-10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038287" comment="dprobes less than 3.6.5-8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038288" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038289" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038290" comment="kernel-bigsmp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038291" comment="kernel-bigsmp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038292" comment="kernel-default-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038293" comment="kernel-default-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038294" comment="kernel-default less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038295" comment="kernel-default less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038296" comment="kernel-docs less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038297" comment="kernel-docs less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038298" comment="kernel-smp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038299" comment="kernel-smp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038300" comment="kernel-smp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038301" comment="kernel-smp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038302" comment="kernel-source less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038303" comment="kernel-source less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038304" comment="kernel-syms less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038305" comment="kernel-syms less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038306" comment="kernel-um-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038307" comment="kernel-um-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038308" comment="kernel-um less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038309" comment="kernel-um less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038310" comment="kernel-xen-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038311" comment="kernel-xen-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038312" comment="kernel-xen less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038313" comment="kernel-xen less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038314" comment="ltmodem less than 8.31a10-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038315" comment="um-host-install-initrd less than 1.0-50.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038316" comment="um-host-kernel less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038317" comment="um-host-kernel less than 2.6.11.4-21.7"/>
		</criteria>
	</criteria>
	<!-- 8a7a62bd2689c5729cb258075912cd07 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032795" comment="kernel-s390 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- 8cb0aa3b1ee5031c67c4ee14f4858126 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- 928c182f4ce54092ec84d122124335ca -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032796" comment="kernel-64k-pagesize less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032797" comment="kernel-debug less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032798" comment="kernel-sn2 less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
		</criteria>
	</criteria>
	<!-- a3b07ca3609dec4a6eaba721000098e2 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038318" comment="k_athlon less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038319" comment="k_debug less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038320" comment="k_psmp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- d47bda72442464a1dede0e81b32d7ca8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
	<!-- d616efaaa3764b063cc5bd3d6d09c89e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030518" comment="kernel-bigsmp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032797" comment="kernel-debug less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032799" comment="kernel-um less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032800" comment="um-host-install-initrd less than 1.0-48.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032801" comment="um-host-kernel less than 2.6.5-7.155.29"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030518" comment="kernel-bigsmp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030514" comment="kernel-default less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030515" comment="kernel-smp less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030516" comment="kernel-source less than 2.6.5-7.155.29"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030517" comment="kernel-syms less than 2.6.5-7.155.29"/>
			</criteria>
		</criteria></criteria>
	<!-- f0f03f02699b998edb62098de7b55696 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038280" comment="k_deflt less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038321" comment="k_itanium2-smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038322" comment="k_itanium2 less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038323" comment="k_page-64k less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038282" comment="k_smp less than 2.4.21-292"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038283" comment="kernel-source less than 2.4.21-292"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050750" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0750</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0750" source="CVE"/>
	<description>
	The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0abece4e7b5340fdb16eda2bcac5a2e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038430" comment="k_deflt less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038431" comment="k_itanium2-smp less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038432" comment="k_itanium2 less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038433" comment="k_page-64k less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038434" comment="k_smp less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038435" comment="kernel-source less than 2.4.21-286"/>
		</criteria>
	</criteria>
	<!-- 6bd3efb74577c58929a9b2fdfbb0de19 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038430" comment="k_deflt less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038436" comment="k_numa less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038434" comment="k_smp less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038435" comment="kernel-source less than 2.4.21-286"/>
		</criteria>
	</criteria>
	<!-- 7e8099fa258d65677612a6866cbceb86 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038437" comment="k_athlon less than 2.4.19-380"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038438" comment="k_deflt less than 2.4.19-380"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038439" comment="k_psmp less than 2.4.19-380"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038440" comment="k_smp less than 2.4.19-380"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038441" comment="kernel-source less than 2.4.19.SuSE-380"/>
		</criteria>
	</criteria>
	<!-- 8018e25a083d0b5870eba427903d4e85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038286" comment="Intel-536ep less than 4.69-10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038287" comment="dprobes less than 3.6.5-8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038288" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038289" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038290" comment="kernel-bigsmp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038291" comment="kernel-bigsmp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038292" comment="kernel-default-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038293" comment="kernel-default-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038294" comment="kernel-default less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038295" comment="kernel-default less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038296" comment="kernel-docs less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038297" comment="kernel-docs less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038298" comment="kernel-smp-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038299" comment="kernel-smp-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038300" comment="kernel-smp less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038301" comment="kernel-smp less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038302" comment="kernel-source less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038303" comment="kernel-source less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038304" comment="kernel-syms less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038305" comment="kernel-syms less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038306" comment="kernel-um-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038307" comment="kernel-um-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038308" comment="kernel-um less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038309" comment="kernel-um less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038310" comment="kernel-xen-nongpl less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038311" comment="kernel-xen-nongpl less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038312" comment="kernel-xen less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038313" comment="kernel-xen less than 2.6.11.4-21.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038314" comment="ltmodem less than 8.31a10-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038315" comment="um-host-install-initrd less than 1.0-50.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038316" comment="um-host-kernel less than 2.6.11.4-21.6"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038317" comment="um-host-kernel less than 2.6.11.4-21.7"/>
		</criteria>
	</criteria>
	<!-- c53f8cd84f3c8c488bfb9e9ca445d6df -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038442" comment="k_athlon less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038443" comment="k_debug less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038430" comment="k_deflt less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038444" comment="k_psmp less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038434" comment="k_smp less than 2.4.21-286"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038435" comment="kernel-source less than 2.4.21-286"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050752" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0752</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0752" source="CVE"/>
	<description>
	The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 76dc0c1abc074e6410c0550425653945 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030527" comment="MozillaFirefox-translations less than 1.0.3-0.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030528" comment="MozillaFirefox less than 1.0.3-0.7"/>
		</criteria>
	</criteria>
	<!-- e5b8998f1696f9ed778917054c4987ed -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038445" comment="MozillaFirefox-translations less than 1.0.3-1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038446" comment="MozillaFirefox less than 1.0.3-1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050754" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0754</title>
	<affected family="unix">
		<platform>SLES SDK 9 for IBM S/390 and IBM zSeries</platform>
		<platform>SLES SDK 9 for IBM iSeries and IBM pSeries</platform>
		<platform>SLES SDK 9 for IBM zSeries</platform>
		<platform>SLES SDK 9 for IPF</platform>
		<platform>SLES SDK 9 for X86-64</platform>
		<platform>SLES SDK 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0754" source="CVE"/>
	<description>
	Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 39d5281a9eef8c99168bc6a04902fe46 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="sles9-sdk is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038447" comment="quanta less than 3.2.1-40.4"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050763" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0763</title>
	<affected family="unix">
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0763" source="CVE"/>
	<description>
	Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 1af8318e3751ba8bdbdac5793b252693 -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
	</criteria>
		<criterion test_ref="oval:org.opensuse.security:tst:2009037995" comment="mc less than 4.5.55-764"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050836" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0836</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0836" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0836" source="CVE"/>
	<description>
	Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5db93924372911db14305b78ea6bd75f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038448" comment="java-1_4_2-sun-alsa less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038449" comment="java-1_4_2-sun-demo less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038450" comment="java-1_4_2-sun-devel less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038451" comment="java-1_4_2-sun-jdbc less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038452" comment="java-1_4_2-sun-plugin less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038453" comment="java-1_4_2-sun-src less than 1.4.2.08-0.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038454" comment="java-1_4_2-sun less than 1.4.2.08-0.1"/>
		</criteria>
	</criteria>
	<!-- b5567e88bcedd66fdf6fc0178b4246a5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009038455" comment="java2-jre less than 1.4.2-144"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038456" comment="java2 less than 1.4.2-144"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
			</criteria>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030529" comment="java2-jre less than 1.4.2-129.14"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030530" comment="java2 less than 1.4.2-129.14"/>
			</criteria>
		</criteria></criteria>
	<!-- dc3d9aad7a9a6df3b2a43d6374b3ca9c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036681" comment="sles9-oes is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038457" comment="java2-jre less than 1.4.2-129.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038458" comment="java2 less than 1.4.2-129.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050876" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0876</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0876" source="CVE"/>
	<description>
	Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.
	</description>
 </metadata>
<!-- 3ed84537a89555d73d7f07b3bd059953 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038459" comment="dnsmasq less than 2.22-0.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050877" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0877</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0877" source="CVE"/>
	<description>
	Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.
	</description>
 </metadata>
<!-- 3ed84537a89555d73d7f07b3bd059953 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009038459" comment="dnsmasq less than 2.22-0.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050916" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0916</title>
	<affected family="unix">
		<platform>SUSE CORE 9 for IBM POWER</platform>
	</affected>
	<reference ref_id="CVE-2005-0916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0916" source="CVE"/>
	<description>
	AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.
	</description>
 </metadata>
<!-- 76b31821f5458d44e4feaa31a71f7c0d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030615" comment="kernel-default less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032815" comment="kernel-iseries64 less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032816" comment="kernel-pmac64 less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032817" comment="kernel-pseries64 less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030616" comment="kernel-smp less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030617" comment="kernel-source less than 2.6.5-7.201"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009030618" comment="kernel-syms less than 2.6.5-7.201"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050941" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0941</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0941" source="CVE"/>
	<description>
	The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 06e6754ef4168e45075415036c96260a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030531" comment="OpenOffice_org-cs less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030532" comment="OpenOffice_org-da less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030533" comment="OpenOffice_org-de less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030534" comment="OpenOffice_org-en-help less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030535" comment="OpenOffice_org-en less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030536" comment="OpenOffice_org-es less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030537" comment="OpenOffice_org-fi less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030538" comment="OpenOffice_org-fr less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030539" comment="OpenOffice_org-gnome less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030540" comment="OpenOffice_org-hu less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030541" comment="OpenOffice_org-it less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030542" comment="OpenOffice_org-ja less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030543" comment="OpenOffice_org-kde less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030544" comment="OpenOffice_org-pl less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030545" comment="OpenOffice_org-pt less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030546" comment="OpenOffice_org-ru less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030547" comment="OpenOffice_org-sk less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030548" comment="OpenOffice_org-sv less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030549" comment="OpenOffice_org-zh-CN less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030550" comment="OpenOffice_org-zh-TW less than 1.1.3-0.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030551" comment="OpenOffice_org less than 1.1.3-0.20"/>
		</criteria>
	</criteria>
	<!-- 1cb647949e71965a7fca785be403b586 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038460" comment="OpenOffice_org-cs less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038461" comment="OpenOffice_org-de less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038462" comment="OpenOffice_org-en less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038463" comment="OpenOffice_org-fr less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038464" comment="OpenOffice_org-it less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038465" comment="OpenOffice_org-nl less than 1.1-100"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038466" comment="OpenOffice_org less than 1.1-100"/>
		</criteria>
	</criteria>
	<!-- 78b94aa93d08fa5175e4ee008ebfe309 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038467" comment="OpenOffice_org-ar less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038468" comment="OpenOffice_org-ca less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038469" comment="OpenOffice_org-cs less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038470" comment="OpenOffice_org-da less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038471" comment="OpenOffice_org-de-templates less than 8.2-157"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038472" comment="OpenOffice_org-de less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038473" comment="OpenOffice_org-el less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038474" comment="OpenOffice_org-es less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038475" comment="OpenOffice_org-et less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038476" comment="OpenOffice_org-fi less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038477" comment="OpenOffice_org-fr less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038478" comment="OpenOffice_org-gnome less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038479" comment="OpenOffice_org-hu less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038480" comment="OpenOffice_org-it less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038481" comment="OpenOffice_org-ja less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038482" comment="OpenOffice_org-kde less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038483" comment="OpenOffice_org-ko less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038484" comment="OpenOffice_org-nl less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038485" comment="OpenOffice_org-pl less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038486" comment="OpenOffice_org-pt less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038487" comment="OpenOffice_org-ru less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038488" comment="OpenOffice_org-sk less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038489" comment="OpenOffice_org-sl less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038490" comment="OpenOffice_org-sv less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038491" comment="OpenOffice_org-tr less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038492" comment="OpenOffice_org-zh-CN less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038493" comment="OpenOffice_org-zh-TW less than 1.9.79-9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038494" comment="OpenOffice_org less than 1.9.79-9.2"/>
		</criteria>
	</criteria>
	<!-- 9963410bcf25668f8c0530ad1536c824 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038495" comment="OpenOffice_org1-ar less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038496" comment="OpenOffice_org1-ca less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038497" comment="OpenOffice_org1-cs less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038498" comment="OpenOffice_org1-da less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038499" comment="OpenOffice_org1-de less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038500" comment="OpenOffice_org1-el less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038501" comment="OpenOffice_org1-en-help less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038502" comment="OpenOffice_org1-en less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038503" comment="OpenOffice_org1-es less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038504" comment="OpenOffice_org1-et less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038505" comment="OpenOffice_org1-fi less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038506" comment="OpenOffice_org1-fr less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038507" comment="OpenOffice_org1-gnome less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038508" comment="OpenOffice_org1-hu less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038509" comment="OpenOffice_org1-it less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038510" comment="OpenOffice_org1-ja less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038511" comment="OpenOffice_org1-kde less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038512" comment="OpenOffice_org1-ko less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038513" comment="OpenOffice_org1-nl less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038514" comment="OpenOffice_org1-pl less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038515" comment="OpenOffice_org1-pt less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038516" comment="OpenOffice_org1-ru less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038517" comment="OpenOffice_org1-sk less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038518" comment="OpenOffice_org1-sl less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038519" comment="OpenOffice_org1-sv less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038520" comment="OpenOffice_org1-tr less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038521" comment="OpenOffice_org1-zh-CN less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038522" comment="OpenOffice_org1-zh-TW less than 1.1.3-4.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038523" comment="OpenOffice_org1 less than 1.1.3-4.2"/>
		</criteria>
	</criteria>
	<!-- baffffbbd5c9d56fd65b77c3f0a5415a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038524" comment="OpenOffice_org-Quickstarter less than 1.0-471.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038525" comment="OpenOffice_org-ar less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038526" comment="OpenOffice_org-ca less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038527" comment="OpenOffice_org-cs less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038528" comment="OpenOffice_org-da less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038529" comment="OpenOffice_org-de less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038530" comment="OpenOffice_org-el less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038531" comment="OpenOffice_org-es less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038532" comment="OpenOffice_org-et less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038533" comment="OpenOffice_org-fi less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038534" comment="OpenOffice_org-fr less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038535" comment="OpenOffice_org-gnome less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038536" comment="OpenOffice_org-hu less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038537" comment="OpenOffice_org-it less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038538" comment="OpenOffice_org-ja less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038539" comment="OpenOffice_org-kde less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038540" comment="OpenOffice_org-ko less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038541" comment="OpenOffice_org-nl less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038542" comment="OpenOffice_org-pl less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038543" comment="OpenOffice_org-pt less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038544" comment="OpenOffice_org-ru less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038545" comment="OpenOffice_org-sk less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038546" comment="OpenOffice_org-sl less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038547" comment="OpenOffice_org-sv less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038548" comment="OpenOffice_org-tr less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038549" comment="OpenOffice_org-zh-CN less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038550" comment="OpenOffice_org-zh-TW less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038551" comment="OpenOffice_org less than 1.9.125-4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038552" comment="ooqstart less than 0.8.3-266.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050961" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0961</title>
	<affected family="unix">
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
	</affected>
	<reference ref_id="CVE-2005-0961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0961" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.
	</description>
 </metadata>
<!-- 54f873ef2a89530d36da39dfe7cfdee6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032818" comment="horde less than 2.2.5-63.4"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050965" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0965</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
		<platform>SuSE Linux Desktop 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0965" source="CVE"/>
	<description>
	The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- c432039b13c44620b98118239ad45b24 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036683" comment="sles8-slec is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038332" comment="gaim less than 0.59-181"/>
	</criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050966" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0966</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0966" source="CVE"/>
	<description>
	The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050967" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0967</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0967" source="CVE"/>
	<description>
	Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5e230eded1ef174de48bf19007cc90a0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038195" comment="gaim less than 0.59.8-80"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038196" comment="gaim less than 0.67-88"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038197" comment="gaim less than 0.75-79.8"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038198" comment="gaim less than 0.82.1-3.6"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038199" comment="gaim less than 1.1.4-4.4"/>
		</criteria></criteria>
	<!-- ed0637feec1572bbe30dd794972df4ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030493" comment="gaim less than 1.0.3-2.6"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050989" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0989</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>SUSE LINUX 10.0</platform>
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989" source="CVE"/>
	<description>
	The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 76dc0c1abc074e6410c0550425653945 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030527" comment="MozillaFirefox-translations less than 1.0.3-0.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030528" comment="MozillaFirefox less than 1.0.3-0.7"/>
		</criteria>
	</criteria>
	<!-- 96e07fa6af4b686482ba97e358c289b9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038553" comment="mozilla-32bit less than 9.3-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038554" comment="mozilla-calendar less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038555" comment="mozilla-devel less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038556" comment="mozilla-dom-inspector less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038557" comment="mozilla-irc less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038558" comment="mozilla-mail less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038559" comment="mozilla-spellchecker less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038560" comment="mozilla-venkman less than 1.7.5-17.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038561" comment="mozilla less than 1.7.5-17.2"/>
		</criteria>
	</criteria>
	<!-- e5b8998f1696f9ed778917054c4987ed -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038445" comment="MozillaFirefox-translations less than 1.0.3-1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038446" comment="MozillaFirefox less than 1.0.3-1.1"/>
		</criteria>
	</criteria>
	<!-- e78305dec0bcd8f57d773b6fc2b0b470 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038129" comment="MozillaThunderbird less than 1.0.8-0.1"/>
		</criteria>
			<criteria operator="AND">
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009037776" comment="suse100 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			</criteria>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038130" comment="MozillaThunderbird less than 1.0.8-0.2"/>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050992" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-0992</title>
	<affected family="unix">
		<platform>SUSE LINUX 9.1 for IA32</platform>
		<platform>SUSE LINUX 9.1 for x86-64</platform>
		<platform>SUSE LINUX 9.2</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SuSE Linux 8.2 for IA32</platform>
		<platform>SuSE Linux 9.0 for AMD64</platform>
		<platform>SuSE Linux 9.0 for IA32</platform>
	</affected>
	<reference ref_id="CVE-2005-0992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0992" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.
	</description>
 </metadata>
<!-- 6d4cc744fc67bb3e24471e675c2dfcb8 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037649" comment="suse82 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038042" comment="phpMyAdmin less than 2.4.0-77"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037652" comment="suse90 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038043" comment="phpMyAdmin less than 2.5.3-38"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037655" comment="suse91 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038044" comment="phpMyAdmin less than 2.5.6-34.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037657" comment="suse92 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038045" comment="phpMyAdmin less than 2.6.0-4.8"/>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038046" comment="phpMyAdmin less than 2.6.1pl3-4.2"/>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051038" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-1038</title>
	<affected family="unix">
		<platform>SUSE LINUX 10.1</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Desktop 10 SP1 for x86</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>openSUSE 10.2</platform>
	</affected>
	<reference ref_id="CVE-2005-1038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1038" source="CVE"/>
	<description>
	crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink.  NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9acb48d1dc03ba4123a90374822692ac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038562" comment="cron less than 4.1-45.18"/>
	</criteria>
	<!-- c2857422a97127436f7c7c580480fe5e -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009037778" comment="suse101 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038563" comment="cron less than 4.1-45.10.3"/>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038564" comment="suse102 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009038565" comment="cron less than 4.1-70"/>
		</criteria></criteria>
	<!-- cadd3204a1931f142398112252630a86 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009036678" comment="sled10 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038563" comment="cron less than 4.1-45.10.3"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051041" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-1041</title>
	<affected family="unix">
		<platform>Novell Linux Desktop 9 for x86</platform>
		<platform>Novell Linux Desktop 9 for x86_64</platform>
		<platform>Novell Linux POS 9</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
	</affected>
	<reference ref_id="CVE-2005-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1041" source="CVE"/>
	<description>
	The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e2c7f08437e0128f5441c08f313e453 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030552" comment="kernel-default less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030553" comment="kernel-smp less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
		</criteria>
	</criteria>
	<!-- 268441775ca440ed04388897a55453d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030552" comment="kernel-default less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032819" comment="kernel-iseries64 less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032820" comment="kernel-pmac64 less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032821" comment="kernel-pseries64 less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030553" comment="kernel-smp less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
		</criteria>
	</criteria>
	<!-- 6a4bf92184a1995238339caee038ef50 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038566" comment="Intel-536ep less than 4.69-10.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038567" comment="kernel-bigsmp-nongpl less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038568" comment="kernel-bigsmp less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038569" comment="kernel-default-nongpl less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038570" comment="kernel-default less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038571" comment="kernel-docs less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038572" comment="kernel-smp-nongpl less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038573" comment="kernel-smp less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038574" comment="kernel-source less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038575" comment="kernel-syms less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038576" comment="kernel-um-nongpl less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038577" comment="kernel-um less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038578" comment="kernel-xen-nongpl less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038579" comment="kernel-xen less than 2.6.11.4-21.10"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038580" comment="ltmodem less than 8.31a10-7.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038581" comment="um-host-install-initrd less than 1.0-50.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038582" comment="um-host-kernel less than 2.6.11.4-21.10"/>
		</criteria>
	</criteria>
	<!-- c7050141b3702832a32e74185b621254 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030556" comment="kernel-bigsmp less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032822" comment="kernel-debug less than 2.6.5-7.202.5"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030552" comment="kernel-default less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030553" comment="kernel-smp less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032823" comment="kernel-um less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032824" comment="um-host-install-initrd less than 1.0-48.12.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009032825" comment="um-host-kernel less than 2.6.5-7.202.7"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009030400" comment="sles9-nld is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009030556" comment="kernel-bigsmp less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030552" comment="kernel-default less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030553" comment="kernel-smp less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
			</criteria>
		</criteria></criteria>
	<!-- e400e6279f02255de204820f5290b8bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032826" comment="kernel-64k-pagesize less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032827" comment="kernel-debug less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030552" comment="kernel-default less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032828" comment="kernel-sn2 less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
		</criteria>
	</criteria>
	<!-- f43a8157eaa3cc5d6ad4e782c86273d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032829" comment="kernel-s390x less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
		</criteria>
	</criteria>
	<!-- fa8599c9b2c6f42f6125cdff8246eb01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032830" comment="kernel-s390 less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030554" comment="kernel-source less than 2.6.5-7.202.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009030555" comment="kernel-syms less than 2.6.5-7.202.7"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051042" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-1042</title>
	<affected family="unix">
		<platform>Novell Linux POS 9</platform>
		<platform>Open Enterprise Server</platform>
		<platform>SUSE CORE 9 for AMD64 and Intel EM64T</platform>
		<platform>SUSE CORE 9 for IBM POWER</platform>
		<platform>SUSE CORE 9 for IBM S/390 31bit</platform>
		<platform>SUSE CORE 9 for IBM zSeries 64bit</platform>
		<platform>SUSE CORE 9 for Itanium Processor Family</platform>
		<platform>SUSE CORE 9 for x86</platform>
		<platform>SUSE LINUX 9.3</platform>
		<platform>SUSE LINUX Retail Solution 8</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM POWER</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for IPF</platform>
		<platform>SUSE Linux Enterprise Server 10 SP1 for x86</platform>
		<platform>SuSE Linux Enterprise Server 8 for AMD64</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IBM zSeries</platform>
		<platform>SuSE Linux Enterprise Server 8 for IPF</platform>
		<platform>SuSE Linux Enterprise Server 8 for x86</platform>
		<platform>SuSE Linux Openexchange Server 4</platform>
		<platform>SuSE Linux School Server for i386</platform>
		<platform>SuSE Linux Standard Server 8</platform>
		<platform>UnitedLinux 1.0</platform>
	</affected>
	<reference ref_id="CVE-2005-1042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1042" source="CVE"/>
	<description>
	Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 07fd95b3f9739b88441090b546febd79 -->
	<criteria operator="AND">
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slrs is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036684" comment="sles8-slss is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036682" comment="sles8-slstd is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036685" comment="slox4 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009036686" comment="unitedlinux-1.0 is installed"/>
		</criteria>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038016" comment="mod_php4-core less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038017" comment="mod_php4-devel less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038018" comment="mod_php4-servlet less than 4.2.2-491"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038019" comment="mod_php4 less than 4.2.2-491"/>
		</criteria>
	</criteria>
	<!-- 2e855be5ae7903ca40477ba01d9c9d02 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032403" comment="core9 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032652" comment="apache-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032653" comment="apache2-mod_php4 less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032654" comment="mod_php4-core less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032655" comment="php4-devel less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032656" comment="php4-exif less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032657" comment="php4-fastcgi less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032658" comment="php4-imap less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032659" comment="php4-mysql less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032660" comment="php4-pear less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032661" comment="php4-session less than 4.3.4-43.44"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032662" comment="php4-sysvshm less than 4.3.4-43.44"/>
		</criteria>
	</criteria>
	<!-- 36e362824c8445edae5f3b24fb94c803 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009037661" comment="suse93 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009038333" comment="apache2-mod_php5 less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038334" comment="php5-devel less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038335" comment="php5-exif less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038336" comment="php5-fastcgi less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038337" comment="php5-pear less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038338" comment="php5-sysvmsg less than 5.0.3-14.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009038339" comment="php5-sysvshm less than 5.0.3-14.9"/>
		</criteria>
	</criteria>
	<!-- 487ffe8f95e8ee6f115c76022fd38247 -->
	<criteria operator="
